All updates
Incident update / Starknet mainnet

The NSTR
incident.

An update on liquidity risk, collateral controls and recovery.

What happened

Today's Nostra incident involved manipulation of an illiquid NSTR market and the use of NSTR as collateral to borrow other assets.

NSTR was already classified as a high-risk feed because of its limited liquidity and available pricing sources. We had previously highlighted these risks to Nostra. Gate.io was removed as a source at Nostra's request, citing illiquidity and manipulation concerns, and source coverage remained limited in the months preceding the incident.

The deviating input reflected a manipulated onchain pool price. Our reconstruction found no decimals or median-calculation error. A price recorded in a thin market does not establish that meaningful amounts of collateral can be liquidated at that price.

Source requirements and collateral risk

Our integration guidance recommends at least three pricing sources, alongside freshness checks and thresholds appropriate to the asset's risk. The affected response had two contributing sources. An enforced three-source minimum would have rejected it.

Source checks are one safeguard. Using an illiquid token as collateral to borrow other assets also requires appropriate collateral eligibility, exposure limits and liquidation-depth assessment. An oracle listing does not establish that an asset is suitable for that use.

Recovery

The attacker's address has been frozen, and we are working on recovery. Recovering funds is the immediate priority. We will share further updates as the situation develops.