In September 2026, Nostra Finance, a Starknet-based lending protocol, was the victim of a price manipulation attack. The attacker was able to borrow an estimated $3.5 million after manipulating the perceived price of the NSTR token.
Inside the Attack
The Nostra Finance hacker began preparing for their attack long before it began, accumulating NSTR and pre-positioning collateral as early as March 2026. This was used to set up a fake liquidity pool on September 17, 2026 for the NSTR/SolvBTC trading pair. The deposited liquidity was about 1.5 SolvBTC, and NSTR’s real market value was approximately $550k.
After setting up the pool, the attacker engaged in twenty minutes of wash trading to pump up the perceived price of NSTR within the pool. In total, this raised the value of the token about 8,000x from $0.006 to $49.5.
Due to issues in how price aggregators like GeckoTerminal select reference pools for token prices, this manipulated pool was selected to source pricing data for the NSTR token. As a result, loans made using NSTR as collateral assumed that it was 8,000x more valuable than the reality.
The attacker deposited some of their collected NSTR tokens and used it to take out loans of ETH, STRK, USDC, USDT, WBTC, and DAI. In total, they were able to extract an estimated $3.5 million from the protocol. Notably, the entire market value of NSTR prior to the hack was only about $550k, meaning that the attacker was able to steal about 6x the total value of the market.
After taking out the bad loans, the attacker bridged about $1.92 million of the stolen tokens to Ethereum. Once the hack was detected, Nostra completely froze its money market to prevent additional exploits. As a result of the attack, the protocol TVL dropped from about $4 million to $710k.
Lessons Learned from the Attack
The Nostra hack was an example of a classic price manipulation attack. The attacker was able to create a pool with thin liquidity and trick price oracles into using that pool as the source for pricing information for a particular token. The thin pool’s value was easily manipulated, allowing the attacker to pump up the perceived value of NSTR and use it as collateral for bad loans.
To manage this threat, money markets and lending protocols should implement guardrails regarding pool liquidity and the pools that can be selected for price feeds. Halborn’s Smart Contract Assessments inspect smart contract code to ensure these types of best practices are implemented. To learn more, get in touch.
