Nostra Halts Starknet Money Market After 8,000x Oracle Pump
Nostra Finance, a lending market on Starknet, paused supply, borrow, withdrawal and liquidation functions on September 17 after an attacker manipulated the price feed for the native NSTR token and borrowed roughly $3.5 million in assets against inflated collateral, per Coinpaprika and The Crypto Times.
The mechanics were a textbook low-liquidity oracle attack: the attacker seeded a fake liquidity pool that priced NSTR roughly 8,000 times above its real market level, then used the inflated collateral value to borrow from Nostra's money market from a single account. CryptoRank's tracker, cited in follow-up coverage, indicates the attacker bridged about $1.92 million of proceeds to Ethereum before markets froze. The damage to the token was structural — NSTR's entire market capitalization fell below $600,000 after the incident was priced in, per The Crypto Times. Cryptonomist's coverage frames the wider lesson for Starknet DeFi: thin native-token liquidity plus an oracle that trusts it equals a borrowable balance sheet that never existed.
MEV Bot Front-Ran a $7.8M rsETH Theft — and Kept It
On September 15, an attacker targeted an Ethereum Safe wallet holding about 2,900 rsETH — roughly $7.8 million, with PeckShield valuing the attempt at $7.81 million — through a vulnerability in a custom Uniswap v4 module, per Parameter and Blockonomi. The MEV bot known as Yoink spotted the malicious transaction in the mempool, paid nearly 19 ETH for the first position in the block, and front-ran the thief — capturing the funds itself.
The twist is that the "rescue" is a rivalry, not a charity: the wallet owner was still relieved of the rsETH, and what happens next depends on negotiation rather than protocol. CoinCentral reported that Kelp DAO froze the receiving address as a precaution, and The Crypto Times reported the freeze ran about 24 hours pending next steps. The incident is the second time this month an MEV operator has converted pure profit-seeking infrastructure into a de facto last line of defense — an accident of incentives that security teams would rather not rely on.
The Week in Numbers
Trackers tallied roughly $20 million in incident losses across the past seven days, led by the rsETH Safe exploit, Nostra's oracle drain, and the coordinated Fetch.ai–NuNet strike covered separately today. The month-to-date figure is dominated by a single large September incident earlier in the month. TRM Labs' half-year count — 207 attacks and $972 million in losses in H1 2026, with infrastructure and operational compromises at 76% of value stolen — remains the defining backdrop: most of the money is not being lost to exotic cryptography, but to keys, oracles, vendors and process.
TrustGrade tracks the security posture of wallet vendors, protocols, and exchanges. Security scans with verified, registry-backed scores arrive with TrustGrade Code Scoring in December 2026.