Morning Edition · Sunday, September 6, 2026Published at 2:01 AM EDT · New York
Vesu says 47 borrowing positions were closed between 04:08 and 04:10 UTC on 4 September, and that its own contracts contained no bug.

Vesu, a lending protocol on the Starknet layer-2 network, said an upstream price source operated by the oracle provider Pragma delivered incorrect data for about two minutes on 4 September. During that window the wrong prices reached several Vesu liquidity pools and made 47 borrowing positions appear eligible for liquidation. Automated liquidator bots took roughly $3 million of collateral before the feed returned to the correct value.
Vesu's assessment is that no contract behaved incorrectly. The liquidation engine executed exactly as written, on inputs that were wrong. The protocol says it is coordinating with Pragma, StarkWare, the Starknet Foundation and the curators of the affected pools to recover the seized assets. It has not said how much is recoverable, how the recovery would work, or whether any liquidator has agreed to return anything. Liquidators who acted through open, permissionless functions have no obligation to give the collateral back.
The pattern repeats. Aave suffered a comparable failure in March, when a stale parameter triggered an estimated $26 million to $27 million of unintended liquidations of wrapped staked ether, after which that protocol reviewed its oracle update rates and fallback logic. In both cases the audited on-chain code was fine and the loss came through a privileged input the protocol trusts by design.
Starknet holds $403.7 million of total value secured, up 7.5% over seven days according to L2Beat, so a $3 million forced liquidation is a meaningful share of the collateral on that network. The incident also raises a governance question. Recovery depends on social coordination among a foundation, an oracle firm and pool curators, which is a reminder of how much of a nominally trustless system runs on identifiable parties agreeing to act.
Vesu, by locating the fault entirely upstream at Pragma before any recovery obligation is settled, and the liquidator operators who keep the collateral while the dispute stays framed as an infrastructure failure rather than a protocol failure.
Part of a tracked trend
Losses Move to Components That Worked as Designed
A growing share of DeFi losses will come not from buggy contract code but from components behaving exactly as specified — oracle forwarders, validator signature sets, governance votes and other trusted off-contract inputs — so audits and bug bounties scoped to on-chain code keep missing the failure surface, and protocols will be repeatedly forced to extend review, scope and monitoring to their privileged operational infrastructure.
Start a discussion in Townsquare.
More from this edition
Nearly all reporting traces to Vesu's own post-mortem, Pragma has deployed a fix without naming the upstream venue that produced the bad price, and $3 million describes collateral seized rather than net loss to borrowers after the debt each position carried is subtracted.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Lenders and borrowers on any chain are exposed to whoever writes prices into the contract, and that party is usually outside the scope of the audits and bug bounties the protocol advertises. The people who lost collateral here made no error in position management. Two outcomes decide the cost of this failure class: either lending protocols add safeguards such as multiple independent feeds, deviation limits and liquidation delays, which reduce capital efficiency, or they keep single-provider feeds and depositors continue to absorb occasional two-minute losses with no recourse.
What to watch
Observations to monitor, not financial advice.
Synthesized from: crypto.news · Cryptonomist
Comments
0No comments yet.