Pluang Nostra Starknet Oracle Exploit Results in $3.5M Theft
Article Content
- •Nostra's lending platform was exploited for $3.5 million due to oracle manipulation.
- •The incident has led to a complete pause of all lending and withdrawal activities.
- •This exploit is part of a larger trend of increasing security vulnerabilities in decentralized finance.
Nostra's lending platform on Starknet was exploited on September 18, 2026, when an attacker manipulated the NSTR price oracle, allowing them to borrow $3.5 million in various cryptocurrencies including Ethereum and Wrapped Bitcoin. The attacker also bridged approximately $1.92 million to Ethereum. In response, Nostra has paused all lending, borrowing, withdrawals, and liquidations while investigating the incident. The total value locked in the platform dropped from $4 million to around $710,632 following the exploit. This incident marks the second oracle attack on Starknet protocols within two weeks, following a previous incident on September 4 that involved a publishing error. The ongoing wave of crypto exploits has resulted in over $1.1 billion in losses in the first half of 2026, highlighting significant security challenges in decentralized finance.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Nostra in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…