T
iTokenly

Nostra (NSTR collateral oracle) hack — September 2026

Verified — 2 sourcesLast checked September 19, 2026

Incident facts

Date of incident
Target typeLending protocol
Loss$3,500,000Price at time of incident
MethodOracle or price manipulationThe price feed for NSTR, a token with a market capitalisation under $600,000, was manipulated so that one account's NSTR counted as collateral for about $3.5m of borrowing
ChainsOther
OutcomeUnresolved

What happened

Nostra, a money market on Starknet, lost about $3.5m on 17 September 2026 when a single account borrowed against NSTR collateral at a manipulated price. Nostra puts the incident at 13:28 UTC and paused lending, borrowing, withdrawals and liquidations.

NSTR traded between roughly $0.0055 and $0.0059 with a market capitalisation between $550,000 and $590,000, so the amount borrowed was more than five times the entire value of the collateral token. The borrower took ETH, STRK, USDC, USDT, wrapped bitcoin and DAIv1. PeckShield traced about $1.92m of it to Ethereum, 234.57 ETH and 1.3m DAI; CertiK put roughly $1.55m as still on Starknet.

Nostra says it is reconciling the impact on each asset and tracing the funds, and that the final loss and any recoveries are not yet known. It warned that it would never send users direct messages or ask them to connect a wallet as part of a recovery process. No bounty or recovery programme has been announced. This is a separate matter from the Pragma oracle incident of 4 September, which was a publishing error rather than deliberate manipulation.

Sources

  1. The Crypto TimesSecondary · retrieved 2026-09-19
  2. GNcryptoSecondary · retrieved 2026-09-19

Changes to this entry

  • Recorded two days after the incident. The amount is the roughly $3.5m borrowed against manipulated NSTR collateral, as reported. Nostra says its own reconciliation is unfinished, so the figure may move.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Nostra (NSTR collateral oracle) hack — September 2026", iTokenly, accessed 2026-09-20, https://itokenly.com/hacks/nostra-nstr-oracle
https://itokenly.com/hacks/nostra-nstr-oracle

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.