An attacker created a fake NSTR/SolvBTC pool, wash-traded it, and hijacked GeckoTerminal's pool-selection logic to print NSTR at ~$49.5 (an ~8,000x pump), then borrowed ~$3.5M from Nostra Finance on Starknet. Nostra fully paused supply, borrow, withdrawal and liquidation.
On September 17, 2026, an attacker exploited Nostra Finance on Starknet via oracle price manipulation. At 05:23 UTC the attacker created a fake NSTR/SolvBTC pool with ~1.5 SolvBTC of one-sided liquidity, wash-traded it between 05:27 and 05:47, and hijacked GeckoTerminal's pool-selection logic to print NSTR at ~$49.5 (up from ~$0.006, an ~8,000x pump). Between 05:48 and 05:50 the attacker borrowed ~$3.5M in ETH, STRK, USDC, USDT, WBTC and DAI. Proceeds were dumped across AVNU, Ekubo and JediSwap between 05:51 and 07:08, and ~2.2M STRK was bridged out via NEAR Intents. Roughly $1.9M was consolidated to an Ethereum address and ~$1.5M was left in the borrow account. Collateral had been accumulated in March and August 2026. GoPlus Security, PeckShield, CertiK and SlowMist all classified the incident as oracle price manipulation. Nostra fully paused supply, borrow, withdrawal and liquidation, and TVL fell from ~$4M to ~$710K.
Proceeds were dumped across the AVNU, Ekubo and JediSwap DEXes, with ~2.2M STRK bridged out via NEAR Intents. Roughly $1.9M was consolidated to an Ethereum address while ~$1.5M remained in the borrow account.