Starknet lending protocol Vesu says an incorrect price feed from Pragma caused the abnormal liquidation of 47 borrowing positions containing about $3m (£2.2m) in collateral.
The liquidations took place between 04:08 and 04:10 UTC on 4 September, during a two-minute failure affecting Pragma’s upstream price source. The faulty data reached several Vesu liquidity pools and made the positions appear eligible for liquidation.
Automated liquidators subsequently removed approximately $3m in collateral before the price feed corrected itself.
Vesu said in an incident disclosure published on 5 September that its contracts “operating as designed” and that the protocol had not suffered a smart contract vulnerability. The company said there was no contract patch to deploy because its liquidation engine had correctly responded to the prices it received.
The Pragma price source returned to the correct value within two minutes and has operated normally since, according to Vesu. The protocol did not initially identify the assets involved or provide a breakdown of the affected pools.
It also did not disclose how far the incorrect prices had moved from market rates, the total debt linked to the liquidated positions or the amount of collateral retained by liquidators. Vesu said a technical report would provide further details about the affected markets and the sequence of on-chain transactions.
Pragma has worked with the relevant organisations to introduce a fix addressing the source of the error, Vesu said. Curators of the affected liquidity pools suspended those markets as a precaution, with the restrictions expected to be lifted after the fix has been reviewed.
Vesu uses isolated and curated lending pools, meaning individual curators decide whether and when each market can reopen. The initial disclosure did not say which curators had suspended their pools or give a timetable for restoring normal activity.
Vesu blames faulty data, not a protocol exploit
In an overcollateralised lending market, borrowers deposit assets worth more than the value of their loans. An external price feed is then used to calculate the value of that collateral and assess the health of each position.
Liquidation can begin when the collateral ratio falls below the minimum level required by the relevant pool. Vesu said the 4 September event happened because incorrect collateral prices were supplied to its contracts, rather than because the liquidation mechanism executed improperly.
The incident underlines the dependence of decentralised finance platforms on blockchain oracles. Smart contracts cannot independently read off-chain market prices and therefore rely on external systems to gather, combine and publish that information on-chain.
An oracle typically performs three tasks: finding the data, aggregating it and delivering the result to the blockchain. A failure at any point can send an inaccurate value to an otherwise functioning smart contract, which may then complete a trade or liquidation as instructed.
A July 2026 liquidation-risk explainer from crypto.news described price data as the central input in calculating a DeFi loan’s health factor. It said stale or manipulated data could lead to a healthy position being liquidated or allow an unsafe position to remain open.
A comparable incident occurred on Aave in March 2026, when a stale parameter caused an estimated $26m to $27m in unintended wstETH liquidations. An August 2026 review of that event said Aave later examined oracle update rates and fallback systems while using several oracle sources for major collateral types.
Vesu has not announced similar changes to its oracle structure. The fix to the underlying Pragma error is the only technical measure confirmed in its initial disclosure.
Recovery discussions under way
Vesu said it was working with Pragma, StarkWare, the Starknet Foundation and the curators of the affected pools in an effort to recover funds collected through the liquidations.
The protocol has not explained how the recovery process will work, how much of the $3m could be returned or whether liquidators had agreed to give back any assets. It has not guaranteed a reimbursement amount or announced a payment date.
Users with deposits in Vesu’s Earn product have been advised to keep their positions open. Vesu said closing an Earn position before the recovery process is completed could make the user ineligible for a refund.
Borrowers whose positions were liquidated during the two-minute window have been told to open a support ticket through Vesu’s Discord server. The protocol has not specified which records users must provide, although wallet addresses and transaction details can be used to identify affected positions on-chain.
The proposed recovery would not amount to an automatic reversal. Blockchain transactions are generally final once confirmed, so any restoration would require recovered assets, voluntary returns from liquidators, funds controlled by the protocol or another compensation arrangement agreed by the parties. Vesu has not said which option it intends to pursue.
For US users, the incident concerns a permissionless DeFi product rather than an insured bank account. The SEC’s Investor.gov website says the FDIC insures deposits at eligible banks but does not protect securities or similar investments against a fall in value.
Vesu has not identified any government-backed protection for affected users. Instead, it has directed them towards its support process and said the organisations involved are working to recover the collateral taken during the abnormal liquidations.
The protocol has also not said whether recovery eligibility will be restricted by nationality or residence. Its guidance applies to borrowers liquidated during the specified period and to Earn depositors seeking to preserve potential refund eligibility.
At network level, Vesu is part of Starknet’s DeFi infrastructure. In June 2026, Starknet identified the lender as one of the protocols supporting its STRK20 privacy rollout, alongside decentralised exchanges avnu and Ekubo and staking provider Endur.
Vesu said it would publish a full technical report after completing its investigation. In the meantime, affected borrowers can submit Discord support tickets, while Earn users have been advised not to close their positions.
