NewsCryptoNostra Finance Money Market on Starknet Reportedly Hit by Price Manipulation Attack

Nostra Finance Money Market on Starknet Reportedly Hit by Price Manipulation Attack

Author: DefiLiban·

Key Takeaways

  • •Security firm CertiK has flagged an alleged price-manipulation attack on Nostra Finance's money market, which operates on the Starknet Layer 2 network.
  • •The affected assets, dollar losses, timing, and exact attack vector remain unconfirmed, and Nostra has not issued an official post-incident report.
  • •Nostra Finance is a lending and borrowing protocol that depends on reliable price inputs to value collateral, determine borrowing capacity, and trigger liquidations.
  • •Price-manipulation exploits can make under-collateralized positions appear fully backed, a risk demonstrated by past incidents such as the 2022 Mango Markets attack on Solana.
  • •Users with open positions should follow Nostra's verified communication channels for news of paused markets, root-cause findings, and remediation steps such as oracle replacements or compensation proposals.
Nostra Finance Money Market on Starknet Reportedly Hit by Price Manipulation Attack

Nostra Finance's money market on Starknet has reportedly been hit by a price-manipulation attack, according to an alert issued by blockchain security firm CertiK. The full scope of the incident — including the affected assets, any dollar losses, and the precise attack vector — remains unconfirmed as of publication.

Reported Target and Incident Status

The reported target is Nostra Finance, a lending and borrowing protocol operating on the Starknet Layer 2 network. Nostra allows users to supply digital assets to earn yield and borrow against collateral, making its money market dependent on reliable price inputs for collateral accounting. Starknet, the network it operates on, is a validity rollup Layer 2 environment built to scale Ethereum-based applications.

The attack has been characterized as price manipulation, a category of exploit in which an attacker distorts on-chain price feeds or oracle readings to extract value from a money market's collateral and borrowing logic. Oracle-driven exploits of this kind have repeatedly affected lending protocols across the decentralized finance sector — the 2022 Mango Markets exploit on Solana remains a widely cited example of how manipulated collateral valuations can translate directly into unbacked borrowing.

The alert originated with a CertiKAlert post on X, published by the security monitoring account of audit firm CertiK. CertiK's alerts flag on-chain activity consistent with known attack patterns, but an alert is not an independent confirmation of loss or root cause.

Details Still to Be Confirmed

The timing of the attack, the specific assets involved, any loss figures, and whether the protocol has paused affected markets are all unconfirmed at this stage. No official post-incident report from the Nostra Finance team has been referenced in the available evidence. In similar incidents, protocols typically follow initial security alerts with formal post-mortems identifying root causes and remediation plans. Users should treat all secondary reporting, including this article, as preliminary until the protocol issues a verified statement.

How Price Manipulation Can Affect a Money Market

Money markets rely on asset price feeds to determine collateral value, borrowing capacity, and liquidation thresholds. If an attacker can artificially inflate or deflate a reported asset price, the protocol's accounting can treat under-collateralized positions as fully backed, enabling outsized borrows or blocking legitimate liquidations. The result is bad debt that the remaining liquidity providers absorb. In several documented incidents across the sector, attackers have used flash loans — uncollateralized loans borrowed and repaid within a single transaction — to obtain the temporary capital needed to distort a thinly traded price feed without committing upfront funds.

The specifics of Nostra's oracle design and any safeguards in place have not been confirmed in the available evidence; money markets commonly rely on multiple price sources, deviation checks, and pause functions to counter this class of risk. For context on how borrowing market design affects protocol risk, Hyperliquid's recent changes to its portfolio margin borrowing model illustrate how protocol-level controls can alter the attack surface for this class of exploit.

Why Verified Post-Incident Details Matter

The actual impact of a price-manipulation attempt depends on which assets were targeted, how the protocol sources its price data, whether circuit-breakers or pause mechanisms activated, and how quickly the team can socialize a response. Until those details are confirmed, loss estimates and attribution circulating on social platforms should be treated as unverified claims.

What Nostra Finance Users Should Monitor Next

Users with open positions on Nostra Finance should check the official protocol interface and the team's verified communication channels for any paused-market notices, parameter updates, or emergency governance actions. Collateral health and liquidation proximity should be reviewed directly through the protocol's dashboard rather than inferred from social media reports.

Key updates to watch include an official incident report from the Nostra Finance team identifying the root cause, any announcement of paused lending or borrowing markets, and remediation steps such as oracle replacements, bad-debt socialization votes, or user compensation proposals. TVL movement on DeFiLlama's Nostra protocol page can serve as an independent proxy for capital withdrawal activity, though it is not a substitute for official protocol communications.