On Thursday an attacker borrowed roughly $3.5 million in ETH, STRK, USDC, USDT, wrapped bitcoin and DAI from Nostra Finance, a lending protocol built on the Starknet network, without ever depositing anything of comparable value. The trick was the collateral itself. The attacker pumped the price of Nostra’s own NSTR token by roughly 8,000 times, from about $0.006 to $49.50, then borrowed against the inflated balance before anyone noticed.
The manipulation ran through the price aggregator GeckoTerminal rather than through Nostra’s code. By building a shallow NSTR to SolvBTC liquidity pool, the attacker hijacked which pool GeckoTerminal treated as the authoritative source for NSTR’s price, so the feed Nostra’s oracle relied on reflected a market the attacker controlled rather than NSTR’s real trading activity. NSTR’s genuine market capitalisation sits under $600,000, smaller than the sum ultimately borrowed against it.
Nostra has fully paused its money market, disabling new supply, borrowing and liquidations while it investigates. The borrowed assets moved through the decentralised exchanges AVNU, Ekubo and JediSwap, and the blockchain security firm PeckShield said around $1.92 million of STRK left Starknet entirely through the NEAR Intents bridge, though that routing has not been independently confirmed elsewhere. It is the kind of oracle manipulation that has become a recurring theme in DeFi lending this year, attacking the price feed rather than the contract.
Nostra has not said whether depositors in the paused market can expect their funds back, or on what timeline the market might reopen. Oracle design was supposed to be the boring, solved part of DeFi lending. A token worth less than $600,000 just proved otherwise.



