Pragma Flagged Oracle Risks After Nostra Exploit
The oracle provider identified critical security vulnerabilities following a $3.5 million exploit on the Starknet network.
Updated on Sept. 22, 2026 in Cybersecurity

Live Poll
Do you trust decentralized lending protocols to protect your deposited funds from exploits?
Pragma has classified six price feeds as critical risk after an attacker successfully manipulated the NSTR oracle price on the Nostra lending protocol. The exploit resulted in $3.5 million in borrowed assets and prompted Nostra to pause all core protocol operations.
Why it matters
The incident highlights systemic risks in decentralized finance where thin market liquidity prevents collateral from being sold at quoted prices. It underscores the danger of overlapping market dependencies between publishers and aggregators during periods of price volatility.
Pragma identified that 6 of 22 mainnet market feeds face critical risks, with individual tokens like LORDS and EKUBO showing 22% and 17% sell-quote deterioration respectively. The exploit succeeded because the protocol lacked an enforced three-source minimum for oracle price responses.
The players
Pragma
An oracle network providing verifiable market data for decentralized finance protocols.
Nostra
A lending and borrowing protocol built on the Starknet blockchain.
The details
The attacker manipulated an on-chain liquidity pool to artificially inflate the reported price of NSTR collateral. Pragma testing revealed that liquidity on these assets is too thin to support current price quotes, with tests using a $10,000 quantity showing significant slippage. An enforced three-source minimum for oracle data—the process by which blockchain protocols receive external price data—would have triggered a rejection of the manipulated input.
Timeline
September 17, 2026: The exploit occurred at the Nostra lending protocol on the Starknet network.
September 18, 2026: Pragma issued a critical risk assessment for six price feeds.
The Tech Race
This incident exposes a security gap in standard oracle implementations that rely on single-source inputs. It reinforces the industry shift toward requiring multi-source data validation to maintain collateral integrity during high-volatility events.
Users of the Nostra protocol currently face a complete freeze of lending, borrowing, and withdrawal capabilities while the network remains paused. These users must monitor future protocol communications for updates regarding potential recovery timelines or liquidation policy changes.
The takeaway
DeFi protocols remain highly vulnerable to oracle manipulation when collateral lacks sufficient liquidity. Investors should watch for upcoming technical audits regarding the implementation of multi-source oracle requirements across Starknet lending platforms.
Further reading
For broader trends in smart contract security, see our coverage in Cybersecurity.
Live Poll
Do you trust decentralized lending protocols to protect your deposited funds from exploits?






