Skip to content
Active Currencies: 21,298
Market Cap: $2.787T
Bitcoin Dominance: 58.36%
24h Market Cap Change: $2.85

Nostra hit by $3.5M Oracle attack as security concerns re-emerge — Details

Here's what went wrong with Nostra’s NSTR Oracle.

Nostra hit by $3.5M Oracle attack as exploiters increase their foothold - Details

Crypto security took another hit today after Nostra’s lending market on Starknet app was reportedly exploited through manipulation of the price feed for NSTR. The attacker was able to do this by scheming the protocol’s oracle to report an inaccurate NSTR value.

Since Nostra uses that oracle’s price to determine how much collateral is worth, the manipulated price apparently made the attacker’s NSTR collateral look more valuable than it really was.

Funds lost and laundered

Once the manipulated NSTR price was accepted by Nostra’s oracle, the attacker was able to use the overvalued NSTR collateral to borrow roughly $3.5 million in Ethereum [ETH], Starkent [STRK], Circle [USDC], Tether [USDT], Wrapped Bitcoin [WBTC], and DAIv1.

Now since the collateral value and borrowing limits were determined using the wrong price, the loans might have seemed legitimate. This allowed the attacker to move a step ahead and bridge about $1.92 million to Ethereum, comprising of 234.57 ETH and 1.3 million DAI.

However, the $3.5 million borrowed is not the final loss reported by the team. Especially as Nostra is still assessing the impact and potential recoveries.

However, as a safety measure, the protocol has paused lending, borrowing, withdrawals, and liquidations while investigating the oracle manipulation. The exact method is yet to be disclosed too.

More incidents over the past 2 weeks

This episode coincided with a recent attack on Revolut, which fell victim to a sophisticated phishing attack after a fraudulent government request passed its security checks.

Meanwhile, Term Finance was attacked after the wrongdoer exploited weaknesses in its DAO governance. Liquid Network’s hack too saw attackers exploit a software flaw to generate around 4,000 BTC.

All about the growing scam epidemic

Cases like these have pushed crypto security losses in H1 2026 to $1.1 billion across more than 212 on-chain incidents. In fact, April alone accounted for over $600 million, led by the KelpDAO and Drift Protocol exploits.

In these 6 months, Ethereum recorded the highest losses worth $332 million, followed closely by Solana at $326 million.

Over the past year, crypto exploits have already resulted in approximately $2.101 billion in total value hacked. Of this amount, around $1.353 billion was lost in DeFi protocols, while cross-chain bridges accounted for a further $758.96 million in hacked funds.

Defi hacks
Source: DeFiLlama

Final Summary

  • Attacker was able to use the overvalued NSTR collateral to borrow roughly $3.5 million in ETH, STRK, USDC, USDT, WBTC, and DAIv1.
  • About $1.92 million to Ethereum, comprising 234.57 ETH and 1.3 million DAI, was also bridged by that attacker. 
Disclaimer: AMBCrypto's content is meant to be informational in nature and should not be interpreted as investment advice. Trading, buying or selling cryptocurrencies should be considered a high-risk investment and every reader is advised to do their own research before making any decisions.

Ishika Kumari

Journalist

Ishika Kumari is a Crypto Analyst at AMBCrypto, specializing in regulatory developments, market dynamics, and blockchain’s real-world impact. She breaks down complex protocols and legislation into practical, easy-to-understand insights.

AMBCrypto was founded in 2018 with a mission to simplify and bring the latest blockchain and cryptocurrency news to our readers. We have quickly grown into the digital news source for an emerging generation of cryptocurrency enthusiasts, reaching more than a million readers on a monthly basis, across the globe.