
AI-generated summary
Pragma provides oracle services for blockchain networks. Nostra is a lending protocol on Starknet that experienced a Sept. 17 exploit where manipulated oracle prices allowed excessive borrowing against NSTR collateral.
Oracle provider Pragma classified 6 of 22 mainnet market and rate feeds as critical risk in a Sept. 18 assessment, warning lenders that an available token price does not establish that collateral can be sold to cover a loan.
The liquidity report followed a Sept. 17 borrowing exploit at Nostra, a lending protocol on Starknet. Nostra’s account reported that a manipulated NSTR oracle price allowed one account to borrow approximately $3.5 million of other assets against NSTR collateral.
Pragma placed BROTHER, DAI, DOG, EKUBO, LORDS and NSTR in its critical category, with nine other feeds rated high risk. The assessment does not establish that every listed feed is used as collateral.
Why an oracle price is not enough
An oracle supplies a valuation. Liquidation requires selling collateral, and a thin market may not absorb that sale near the quoted price. A loan can be backed by an apparent value that cannot be realized when repayment depends on selling the token.
At token quantities valued by the oracle at $10,000, sell-quote deterioration was about 15% for NSTR, 17% for EKUBO, 22% for LORDS, and 20% for BROTHER, measured against quotes for $10 sales.
The DAI finding concerns source concentration and tested Starknet token routes. Current and legacy deployments had different exit curves, so the critical rating cannot be read as a finding that DAI is globally illiquid.
Multiple source labels also don't necessarily solve the problem. Pragma warns that publishers and aggregators can share underlying market dependencies, so several labels may reflect overlapping liquidity.
In its Sept. 17 incident account, Pragma said the affected oracle response had two contributing sources. The provider said an enforced three-source minimum would have rejected it, and its integration guidance also recommends freshness checks and thresholds suited to the asset’s risk.
Rejecting that response would be a separate safeguard from ensuring collateral has adequate sale liquidity.
Pragma attributed the deviating input to a manipulated on-chain pool and said its reconstruction found no decimals or median-calculation error.
For depositors, the immediate consequence was restricted access. In its Sept. 17 statement, Nostra said it paused lending, borrowing, withdrawals, and liquidations while it reconciled the impact and traced funds. It said final losses and potential recoveries were still unknown.
The Sept. 17 announcement leaves the subsequent status of withdrawals and recovery unconfirmed.
In its update that day, Pragma separately reported that the attacker’s address had been frozen and recovery work was ongoing.
The report leaves lenders with a decision beyond whether a feed exists: which assets qualify as collateral, how much exposure to allow, and whether their exit liquidity can support liquidation. Publishing a price doesn't settle any of those questions by itself.
AI outlook — possibilities, not facts
Nostra will resume lending and borrowing activities after completing impact reconciliation and fund tracing
Likely · Within weeks
Pragma will implement stricter oracle integration guidelines including three-source minimums and asset-specific freshness thresholds
Very likely · Within months

A malicious iOS app named FomoPeek, distributed through Apple's App Store, was found to contain kernel exploits that stole nearly $580,000 in cryptocurrency by accessing wallet data and Keychain information, according to a SlowMist investigation with OKX security team.

XRP Ledger validators have conditionally activated the BatchV1_1 amendment for Sept. 29 at 14:06:41 UTC, converting a previously identified security flaw into a live test of the network's amendment process. The fix addresses a critical authorization vulnerability that could have allowed unauthorized transactions if activated on mainnet. Activation depends on maintaining over 80% validator support for two weeks, with current support at 30 of 35 trusted validators. The update enables atomic transaction flows while requiring client software upgrades to avoid consensus disruption.

Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman are expected to brief the UN Security Council on Wednesday on AI risks and international security implications, with Hugging Face CEO Clément Delangue and Yoshua Bengio also participating. Chinese AI firms DeepSeek and Moonshot have been invited to speak, though DeepSeek's founder will not attend. France is convening the meeting as global concerns grow over advanced AI systems and potential loss of human control.

Blockchain security firm SlowMist discovered malicious code in versions 1.1 and 1.2 of the FomoPeek iPhone app, which was distributed via Apple's App Store and marketed as a cryptocurrency transaction tracker. The app contained hidden modules enabling iOS sandbox escapes to steal private keys and sensitive data, leading to approximately $579,900 in USDT theft traced to attacker address 0x6d37f2C5e8F8546b648D317295565dA95975f4BB. Crypto platforms including Binance and OKX have warned users to remove the app, update iOS, and move assets to new wallets.

The UN Security Council will hear briefings from AI executives including Sam Altman, Dario Amodei, Yoshua Bengio, and Clément Delangue on risks posed by artificial intelligence, such as autonomous cyberattacks, election interference, and weapon design. The session, organized by France, also includes invited statements from Chinese firms DeepSeek and Moonshot. Amodei advocated for slowing AI development and restricting chip exports to China, while Trump dismissed AI risks as a 'hoax'.

White-hat actors have moved 40.71 BTC worth $3.31 million from the Coldcard hardware wallet exploit into a recovery effort labeled 'Crypto Recovery Trust,' according to Galaxy Research. The funds represent 2.8% of the total $130 million theft stemming from a 2021 firmware flaw that generated weak seed phrases on Coinkite devices.