Nostra's lending market on Starknet experienced a security breach after an attacker manipulated the protocol's price oracle to report an inaccurate value for NSTR. The exploit allowed the attacker to artificially inflate the worth of NSTR collateral, enabling unauthorized borrowing from the protocol.
By using the overvalued NSTR as collateral, the attacker borrowed roughly $3.5 million in Ethereum (ETH), Starknet tokens (STRK), Circle (USDC), Tether (USDT), Wrapped Bitcoin (WBTC), and DAIv1. The attacker subsequently bridged approximately $1.92 million to Ethereum, comprising 234.57 ETH and 1.3 million DAI.
Nostra paused lending, borrowing, withdrawals, and liquidations while investigating the oracle manipulation. The protocol stated it is still assessing the full impact and potential recoveries, indicating the final loss figure may differ from the initial $3.5 million borrowed.
Broader Security Concerns
The Nostra incident follows several other high-profile exploits in recent weeks. Term Finance was targeted through weaknesses in its DAO governance, while Liquid Network's hack exploited a software flaw resulting in the generation of approximately 4,000 BTC.
Crypto security losses reached $1.1 billion across more than 212 on-chain incidents in the first half of 2026, with April alone accounting for over $600 million in losses. Over the past year, crypto exploits have resulted in approximately $2.101 billion in total value hacked, with DeFi protocols accounting for $1.353 billion and cross-chain bridges for $758.96 million.


