h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

Oracle Manipulation Went Multi-Chain: Starknet’s $3.5M Hit

A $3.5 million exploit on Starknet's Nostra Finance showed oracle manipulation is no longer an Ethereum problem. In 2026 it went multi-chain, and every new network relearns the same lesson.

A thin token, a young chain, and $3.5 million

On September 17, 2026, someone turned roughly half a million dollars of a barely traded governance token into a $3.5 million loan they never meant to repay. The target was Nostra Finance, the largest money market on Starknet, Ethereum’s zero-knowledge rollup. The method was the oldest trick in DeFi: inflate the price of a thin collateral token, borrow genuinely liquid assets against the phantom value, and leave before the price snaps back.

What made the Nostra hit worth writing about was not the size. At $3.5 million it barely registers next to the $75 million drained from Cronos lending protocol Tectonic three weeks earlier, and it landed even as the wider market enjoyed a calm stretch that had Bitcoin grinding through a bullish Uptober. It mattered because of where it happened. Nostra runs on Starknet, a Cairo-based rollup with its own oracle provider, Pragma, and its own young set of lending markets. The attack that emptied it is functionally identical to the one that hit bZx on Ethereum in February 2020. Six years and a dozen chains later, the same exploit still works, and in 2026 it has been working on networks that did not exist when the pattern was first documented.

That is the story worth telling in October 2026: oracle manipulation stopped being an Ethereum problem. It went multi-chain. Every new high-performance network, every new oracle design, every fresh crop of lending markets seems to rediscover the lesson on its own, usually at a cost of several million dollars.

What actually happened to Nostra

The mechanics were clean. NSTR, Nostra’s native token, traded around $0.006 and carried a total market value well under $600,000. The attacker routed buys through a shallow pool (reporting pointed to a thinly funded NSTR/SolvBTC pair) until Nostra’s price feed read NSTR at roughly $49.50, close to 8,000 times its real value, with one tracker clocking the move at 8,306x.

With NSTR marked up that far, the attacker’s deposit registered as collateral worth millions. They then borrowed a basket of liquid assets against it, ETH, STRK, USDC, USDT, WBTC and DAI, roughly $3.5 million in all, against collateral that in the real market was worth about $546,000, per CryptoSlate. The gap between those two numbers was the theft.

Nostra paused lending, borrowing, withdrawals and liquidations within hours, saying final losses and recoveries were still unknown. The next day its oracle provider, Pragma, published something more damning than a single post-mortem: a review of 22 live price and rate feeds across Starknet DeFi that rated six of them (BROTHER, DAI, DOG, EKUBO, LORDS and NSTR) as critical risk, with nine more flagged high risk. The NSTR feed was not a lone weak link. On a young chain with thin liquidity, more than a quarter of the audited feeds carried the same flaw.

The oracle did its job, and that was the problem

Here is the uncomfortable part. Pragma’s feed was not hacked. It reported the price of NSTR accurately, because by the time the attacker was done, $49.50 really was the going rate in the pool the feed was watching. The oracle told the truth about a market that had been bent into a lie.

Pragma put it plainly in its review: “an available token price does not establish that collateral can be sold to cover a loan.” That one sentence is the whole subject. A price feed answers what an asset is trading at right now; a lending market needs the answer to a different question: if the borrower defaults, can the protocol actually sell the collateral for what the feed says it is worth? Those are not the same question, and in 2026 the gap between them became the single most expensive misunderstanding in DeFi.

The industry keeps restating the lesson in different voices. “The oracle was not wrong. It accurately reported the price of TONIC on the pool it was reading from at that moment,” RedStone co-founder Marcin Kazmierczak told crypto.news after the $75 million Tectonic exploit on Cronos in August. Reporting a price and validating that a price is safe to lend against, he argued, are two different jobs. Pragma, a different oracle on a different chain, reached the identical conclusion a month later.

Oracle manipulation, defined

For readers new to the category, a quick grounding. Smart contracts cannot see the outside world; they do not know the dollar price of ETH or the exchange rate of a stablecoin unless something feeds the number in. That something is an oracle. A lending market uses it to decide how much you can borrow against your collateral and when you should be liquidated. If an attacker can bend the number the oracle reports, they can trick the protocol into lending far more than the collateral is worth.

Feeds get built in a few broad ways, and each has failure modes. A spot oracle reads the current price straight from an on-chain pool; it is cheap and immediate but trivially gamed if the pool is thin. A time-weighted average price, or TWAP, averages over a window to blunt single-block spikes; it resists a one-block flash-loan pump but can still be dragged over several blocks and lags during fast moves. External oracle networks (Chainlink, Pyth, RedStone, API3, Supra, Pragma and others) try to sidestep both by sourcing prices off-chain from many venues and delivering a median or aggregate on-chain.

Flash loans get blamed for these attacks, and they are the accelerant, not the flaw. A flash loan lets an attacker borrow millions with no collateral as long as it is repaid in the same transaction, which supplies the capital to move a thin market. But you do not always need one: the Tectonic attacker pumped a token roughly 100-fold with only about $600,000 of their own money, according to crypto.news. The real vulnerability is a protocol trusting a price that one actor can move. The OWASP Smart Contract Top 10 lists price oracle manipulation as SC03 for 2026, where it has sat near the top for years.

Stripped to its skeleton, the classic attack runs inside a single transaction and takes five steps. First, the attacker picks a target: a lending market that accepts a thin token as collateral and prices that token from a shallow on-chain pool. Second, they borrow the ammunition, usually a flash loan large enough to overwhelm the pool and repayable in the same transaction. Third, they swap into the pool and spike the quoted price, and the oracle dutifully reads the new number. Fourth, they deposit the now-overvalued token as collateral and borrow out blue-chip assets up to the inflated limit. Fifth, they keep the borrowed assets, repay the flash loan from them, and walk away. When the pump unwinds, the collateral is worth a fraction of the debt and the protocol is left holding the gap as bad debt.

Every 2026 incident is a variation on that template. Tectonic skipped the flash loan and used about $600,000 of the attacker’s own capital, which was enough because the TONIC pool was so shallow. Donation attacks skip the swap and inflate a vault’s internal exchange rate instead. The signature-forging attacks skip the market altogether and simply hand the contract a fake number. What stays constant is the hinge between steps three and four: a protocol that will lend against a price it has not checked against real, sellable liquidity. Remove that hinge and the other four steps lead nowhere.

The attack went multi-chain

For most of DeFi’s history, oracle manipulation was an Ethereum story, then an Ethereum-and-its-rollups story. That is no longer true. Blockchain-intelligence firm TRM Labs counted 32 price-manipulation exploits in 2026 through early September, against just 12 in all of 2025, in figures relayed by KuCoin. By TRM’s tally the category now accounts for roughly one in eight crypto hacks, up from about one in 17 in 2022. The attacks are not only more frequent; they are spread across more chains than ever.

Run down the 2026 roster and the striking thing is how few victims sit on Ethereum mainnet. YieldBlox was on Stellar. Rhea was on NEAR. Bonzo was on Hedera. Tectonic was on Cronos. Moonwell was on Base. Nostra was on Starknet. Even the genre-defining case, Mango Markets, was on Solana. Each is a different virtual machine, a different oracle stack, a different developer community, and each learned the lesson separately.

ProtocolChain / VMDateApprox. lossHow the price movedWhere it broke
bZxEthereumFeb 2020~$350KThin ETH market, flash loanSpot DEX price
Mango MarketsSolanaOct 2022~$110MSelf-trading pumped MNGO 13x+ in 30 minSpot oracle, manipulated venues
UwU LendEthereumJun 2024~$19.3MsUSDe via Curve, ~40,000 ETH flash loanDerived pool price
Polter FinanceFantomNov 2024~$12MBOO spot pumped via flash loanSingle-pool spot price
Venus (wUSDM)ZKsyncFeb 2025~$717K bad debtERC-4626 donation, rate 1.06 to 1.7Derived vault share price
YieldBloxStellarFeb 2026~$10.2MLone market maker exited; one ~100x sellVWAP feed, thin market
Rhea FinanceNEARApr 2026~$7.6MFake token contracts, self-funded poolsValidation layer
BonzoHederaJul 2026~$9MForged all-zeros signature on updateOracle verifier bug
TectonicCronosAug 2026~$75MTONIC pumped ~100x with ~$600KSingle-pool spot price
MoonwellBaseAug 2026~$8.7MMAMO pumped ~40x against a shallow bookSpot price, thin liquidity
NostraStarknetSep 2026~$3.5MNSTR pumped ~8,000x in a thin poolSpot feed, no liquidity check

The pattern is not that these chains are badly built. It is that a lending market is only as safe as the least liquid asset it accepts as collateral, and new chains launch with lots of thin, freshly listed tokens and not much depth behind them. That combination is catnip for this exact attack. It is the same reason so many newly listed tokens are dangerous to hold in the first place, a dynamic we covered in Why Most New Token Listings Lose You Money in 2026. Write-ups for the newer non-EVM cases come largely from security firm Halborn, whose YieldBlox post-mortem reads almost identically to its Ethereum reports from years earlier.

Every new oracle design relearns the same lesson

New chains tend to arrive with new oracle providers, and each provider re-encounters problems the older ones already bled through. Starknet leans on Pragma. Stellar’s Blend markets used Reflector, whose volume-weighted feed was gamed in the February 2026 YieldBlox exploit after the sole market maker pulled liquidity and a single sell order printed a price around 100 times higher. Hedera’s Bonzo relied on Supra. NEAR’s Rhea had its own validation layer. None of these were built by careless teams, but each shipped before its edge cases had been attacked in the wild, which is how edge cases tend to get found.

Provider / methodModelIntended manipulation defenseWhere it still fell short
Naive spot (DEX pool)Single on-chain pool readLittle to nonebZx, Polter, Tectonic, Moonwell, Nostra
TWAPTime-averaged on-chain priceBlunts single-block spikesMulti-block drag; lags fast moves
ChainlinkPush, decentralized node network, median of many sourcesNeeds majority-operator collusion to corruptCorrect feed still mispriced derived wrappers (Edel)
PythPull, first-party publishers with confidence intervalsMany publishers; staleness and confidence signalsOnly as safe as the consuming protocol’s checks
SupraOn-demand pull, signed reportsCryptographic signaturesVerifier accepted an all-zeros signature (Bonzo)
Pragma (Starknet)Aggregated feedsMedian across sourcesSingle-source response accepted; no liquidity check (Nostra)
API3 / RedStoneFirst-party / modular pullSource transparency; OEV auction (API3)Still needs protocol-side risk limits

The providers increasingly say the quiet part out loud: a feed is a data source, not a risk manager. Pragma’s post-incident recommendation for Starknet was not to trust it more but to trust any single feed less. It proposed an enforced three-source minimum that would have rejected the manipulated NSTR response outright, plus freshness checks and per-asset risk thresholds. That is an admission that the oracle layer alone cannot carry the weight protocols have been putting on it.

The liquidity problem hiding inside the price

The deepest version of the Nostra lesson is about liquidity, not price. Pragma’s review included a detail most post-mortems skip: it measured how far the quoted sell price would move if someone actually tried to liquidate a position sized to the oracle valuation. At a notional $10,000, unloading NSTR would move the price about 15 percent; EKUBO about 17 percent; BROTHER about 20 percent; LORDS about 22 percent. Those are ruinous slippage numbers for a liquidation engine that assumes it can sell collateral near the marked price.

This is why the most effective 2026 mitigation is not a better price feed at all; it is a borrow cap tied to executable liquidity. If a market only lets you borrow against a token up to the amount that could realistically be liquidated into the real order book, inflating the token’s quoted price buys the attacker nothing. Kazmierczak framed the fix after Tectonic in exactly those terms: caps pinned to liquidity that actually exists, not to a number on a screen. It is a cheap idea that remarkably few young markets ship with.

Mature markets already encode versions of this. Aave’s isolation mode lets a new or risky asset be listed only as collateral for a capped amount of stablecoin borrowing, so a single manipulation can never scale past a hard ceiling. Supply and borrow caps, debt ceilings and per-asset loan-to-value tiers do the same job from different angles. The common thread is that they treat a listed token’s quoted price as a starting point to be discounted by how much of it could really be sold in a stress event, not as gospel. The markets drained in 2026 almost all shared one trait: they onboarded a token and trusted its price before modeling what liquidating a large position in it would actually fetch.

When the feed itself is forged

Not every 2026 attack bothered to move a market. A newer and more alarming class skips the economics entirely and forges the data on the way into the contract. In July, lending protocol Bonzo on Hedera lost about $9 million when an attacker submitted a price update to Supra’s on-demand oracle that inflated the price of the SAUCE token by roughly twelve orders of magnitude. The signature on that update was made entirely of zeros; Supra’s verifier contract had a bug and accepted it anyway, per CoinDesk. No flash loan, no pool to drain, just a forged message a broken lock let through.

A separate Arbitrum exploit on the perpetuals venue Ostium made the same point from the other direction: there the attacker did not forge a signature but used a compromised oracle signer key to push future-dated, signed price reports through a legitimate forwarder. When the key that signs the feed is the thing that is stolen, the cryptography works perfectly and still produces a lie.

This is the shift security researchers have been warning about. The attack surface is moving, the security firm CredShields observed, “up the stack to governance, to signers, and to the people building the protocols themselves.” CertiK co-founder Ronghui Gu put the blunt version in his firm’s mid-year report: “A protocol can pass a flawless code audit and still lose millions because of a compromised admin key.” CertiK put first-half 2026 losses above $1.31 billion across 344 incidents, with stolen keys and hijacked front ends increasingly rivaling contract bugs. The same lesson haunts cross-chain infrastructure, where the signing and messaging layers, not the smart contracts, leak the money, a failure mode we walked through in The Unaudited Bridge.

What makes the feed-forging class so unsettling is that it breaks the intuition behind every economic defense. Borrow caps, TWAPs and liquidity checks all assume the attacker has to move a real market, which costs money and leaves a trail. Forge the data at the source and none of that applies: the fake price arrives pre-blessed by a valid-looking signature, the contract accepts it in a single block, and the only thing between the attacker and the treasury is the correctness of a verifier most users never think about. Real-time transaction screening from firms like Blockaid has caught some of these mid-attack, but prevention still comes down to getting the boring cryptography exactly right.

Derived prices and donation attacks

A third 2026 flavor manipulates a number that was never really a market price to begin with. Modern DeFi is full of derived values: the share price of an ERC-4626 yield vault, the exchange rate of a wrapped or restaked token, the ratio between a liquid-staking receipt and its underlying. Protocols treat these as prices, but they are accounting outputs, and anyone who can nudge the inputs can nudge the number.

The classic version is a donation attack. In February 2025, an attacker used a roughly $4 million flash loan to repeatedly donate into the wUSDM vault on ZKsync, dragging its exchange rate from 1.06 to 1.7 and self-liquidating for profit; Venus absorbed around $717,000 in bad debt, The Block reported. In July 2026 the same mechanism inflated the wrapper around tokenized Google stock on Edel Finance, and here the nuance matters: Chainlink’s underlying price feed for the stock was correct the entire time, per CoinDesk. The flaw was in the wrapping ratio, not the oracle. The protocol was reading an internal accounting number as if it were a market quote.

The standard fix, Aave’s Correlated-Asset Price Oracle (CAPO), caps how fast a derived exchange rate may grow, which neuters donation spikes. But it adds its own fragility. Yoni Keselbrener of eOracle cautioned in the same analysis that defenses like CAPO demand “additional code complexity and ongoing management,” and Aave proved the point in March 2026 when a misconfigured CAPO snapshot left wstETH undervalued by about 2.85 percent and triggered roughly $26 million in unwarranted liquidations with no attacker involved at all. Chaos Labs founder Omer Goldberg pledged that every affected user would be made whole. These derived-price risks are exactly why the restaking boom carried a hidden fragility beneath its yields, something we traced in Restaking in 2026.

This is the frontier most likely to grow, because tokenized real-world assets multiply the number of derived values in the system. Every tokenized stock, treasury bill or money-market fund arrives wrapped in at least one ratio, and each wrapper is a place where an accounting number can be mistaken for a market price. The underlying Chainlink or Pyth feed can be flawless and the protocol still loses money if it reads the wrapper’s internal rate without asking whether that rate can be gamed. As real-world assets move from pilots to serious collateral, the Edel pattern is likely to repeat on much larger balance sheets than a half-million-dollar Google-stock vault.

OEV, manipulation’s legitimate twin

There is a way of profiting from an oracle update that is not an attack at all, and understanding it explains a lot about why these systems are shaped the way they are. Every time an oracle pushes a new price, it can flip positions into liquidation. Whoever acts first on that update, by liquidating the newly underwater borrower, captures value. That value is Oracle Extractable Value, or OEV, a cousin of the MEV that bots extract from ordering transactions.

For years OEV leaked to a competitive pack of liquidation bots that paid it onward to block builders as priority fees. In 2026 the oracle providers decided to capture it themselves and hand it back to protocols. Chainlink’s Smart Value Recapture (SVR) auctions the right to act on a feed update and returns the proceeds; by Chainlink’s own figures it has processed more than $460 million in liquidations and recaptured over $10 million that would otherwise have leaked to searchers, according to a Chainlink release. In January 2026 Chainlink acquired the Atlas order-flow-auction system from FastLane to extend SVR beyond Ethereum to Arbitrum, Base, BNB Chain and HyperEVM. “Uniting Atlas’s proven order flow auction technology with Chainlink SVR creates the most effective value recapture system DeFi has ever had,” said Johann Eid, chief business officer at Chainlink Labs. Most of the recaptured value flows back to the protocol itself, with the remainder shared between Chainlink and the block builders who order the transactions.

The twist is that SVR now routes the overwhelming majority of OEV recapture, upward of 99 percent by Chainlink’s own account. That is efficient, and it also concentrates a sensitive piece of the liquidation pipeline in one provider’s hands. Rivals such as API3, with its OEV Network auction, exist, but the gap is wide. For a category whose entire problem is over-reliance on a single trusted source, letting one company sit astride both the price feed and the value its updates create is a governance question the industry has not fully reckoned with.

For users, OEV recapture is mostly good news: value that used to vanish to anonymous bots now flows back to the protocols whose users generated it, which can subsidize fees or seed insurance funds. Pyth has pushed its own Express Relay auction toward the same end, and API3 bakes OEV directly into its first-party feeds. The open question is governance rather than mechanics. When one provider both publishes the price and runs the auction for the value that price creates, the incentive to fine-tune update timing in its own favor is at least theoretical, and the protocols relying on it have little visibility into the auction internals. A tool built to reduce trust in intermediaries has quietly created a powerful new one.

Who pays, and who answers for it

When the oracle is right and the loss is real, accountability becomes a genuinely hard question, and 2026 produced no consistent answer. Sometimes the chain itself intervenes: after Tectonic, Cronos validators halted the network and rolled back more than 10,000 blocks to a pre-exploit snapshot, recovering most of the funds and reopening the oldest debate in crypto about whether immutability means anything if a validator set can vote it away. Sometimes a stablecoin issuer steps in: Tether froze several million dollars of the funds fleeing Rhea Finance on NEAR. Sometimes the protocol simply eats the loss and promises reimbursement, as Aave did after its CAPO glitch.

The law is messier still. The genre-defining case remains Mango Markets, where Avraham Eisenberg drained about $110 million in October 2022 by trading against himself to pump MNGO; the CFTC noted the manipulated oracle price jumped more than 13-fold during a 30-minute span. A jury convicted him in 2024, but in May 2025 a federal judge vacated every count, partly on venue and partly on the finding that a permissionless protocol with no terms of service and no rule against what he did gave prosecutors no misrepresentation to point to. In late 2025 prosecutors appealed to the Second Circuit, arguing the ruling would unsettle traditional understandings of fraud. That appeal is still pending, and until it resolves, whether manipulating a DeFi oracle is a crime or a clever trade is formally unsettled in US law.

For US readers it also lands in the gap between the SEC and the CFTC. A manipulated governance token might be a security or a commodity, and the agencies have never cleanly divided the turf, which is part of why enforcement in this corner of the market has been so uneven. The industrial scale of on-chain crime more broadly, from oracle exploits to the forced-labor pig-butchering networks draining victims through crypto rails, has outrun the legal machinery meant to address it.

Whether that machinery catches up may hinge less on the courts than on Congress. Market-structure legislation that would finally divide oversight of digital assets between the SEC and the CFTC has been debated for years without passing, and until it does, every oracle-manipulation case sits in the same gray zone the Mango prosecution exposed: a token that looks like a commodity to one agency and a security to the other, drained on a protocol that answers to neither. Victims, in the meantime, rely on the kindness of white hats and the reach of stablecoin freeze functions. Several 2026 attackers returned funds after being promised a bounty and no referral to law enforcement, a workaround that works precisely because the formal route is so uncertain.

The defender’s playbook

If there is good news, it is that the defenses are well understood; the problem is adoption, not research. A protocol serious about not becoming the next row in the incident table layers several of these:

  • Use multiple independent sources and take a median, so no single pool or publisher can move the number. Pragma’s three-source minimum is this idea.
  • Prefer manipulation-resistant delivery: a robust TWAP resists single-block spikes, while a first-party network with confidence intervals or median aggregation across many nodes raises the cost of collusion.
  • Add freshness and deviation checks: reject stale updates and halt trading when a price moves implausibly far in one step. The Bonzo all-zeros update should never have cleared a verifier, and a sanity bound is the backstop when one does.
  • Tie borrow caps to executable liquidity, not quoted price. This is the single mitigation that would have stopped Nostra, Tectonic and Moonwell outright.
  • Treat derived values as derived: cap the growth rate of vault shares and wrapper ratios, and use ERC-4626 virtual-share patterns to defang donation attacks.
  • Secure the signers and the governance. Most of the biggest 2026 losses came through stolen keys and misconfigurations, not clever math, so key management, timelocks and multisig discipline now matter as much as the pricing logic.

None of this is exotic. The firms that audit these systems publish the same checklist after every incident. The recurring failure is that a new chain or a new protocol ships before it has internalized a list written in other teams’ losses.

The oracle problem is a maturity problem

Expect the multi-chain spread to continue, because the conditions that produce it are structural. Every quarter brings new high-throughput chains, new rollups, new app-specific networks, each launching lending markets against thin, freshly listed collateral served by a young oracle. Until pinning loans to real liquidity becomes a default rather than a lesson, the incident table will keep gaining rows in new columns.

Two trends are worth watching. The first is consolidation: as OEV recapture concentrates in Chainlink’s SVR at upward of 99 percent, the oracle layer is becoming both more professional and more centralized, trading one risk for another. The second is the accountability vacuum. Sergey Nazarov, Chainlink’s co-founder, warned back in 2020 that the only reason these very dangerous patterns were not more discussed was that the losses had not been Mt. Gox level, he told The Defiant. Six years on, the losses run into the billions a year across trackers, the attacks have gone multi-chain, and the law still cannot say for certain whether draining a protocol through its price feed is theft or strategy. The code, meanwhile, keeps doing exactly what it was told. That has always been the problem.

Frequently Asked Questions

What is oracle manipulation in DeFi?

Oracle manipulation is an attack where someone distorts the price data a smart contract relies on, usually by inflating a thinly traded token in a shallow pool, then borrows real assets against the fake value before the price corrects. The oracle itself is often working correctly; it simply reports a price an attacker has bent.

How did the Nostra Finance exploit on Starknet happen?

On September 17, 2026, an attacker pumped Nostra’s NSTR token roughly 8,000-fold in a thin pool, so collateral worth about $546,000 registered as millions. They borrowed around $3.5 million in ETH, STRK, USDC and other liquid assets, then left. Nostra paused its market, and the oracle provider Pragma later flagged six of 22 Starknet feeds as critical risk.

Do flash loans cause oracle manipulation attacks?

No. Flash loans supply cheap capital to move a thin market, so they amplify these attacks, but they are not the root cause. The Tectonic attacker on Cronos pumped a token about 100-fold using roughly $600,000 of their own money and no flash loan. The real flaw is a protocol trusting a price that a single actor can move.

Which oracle is safest, Chainlink or Pyth?

There is no single safe oracle. Chainlink uses a decentralized network and median aggregation, Pyth uses first-party publishers with confidence intervals, and others take different approaches, but any design can be misused if the consuming protocol skips liquidity checks, freshness checks and sensible borrow caps. Safety comes from how a protocol uses a feed, not from the brand alone.

Is manipulating a DeFi oracle illegal?

It is legally unsettled in the United States. A jury convicted Mango Markets exploiter Avraham Eisenberg in 2024, but a federal judge vacated every count in 2025, finding that a permissionless protocol with no rules gave prosecutors no clear misrepresentation. Prosecutors appealed to the Second Circuit in late 2025, and that appeal is still pending.

By Marcus Halloran, senior markets and security correspondent, HOGE Wire.

Share 𝕏 Post Telegram