Crypto

Vesu oracle incident triggers $3M in liquidations


Starknet lending protocol Vesu has reported that a faulty Pragma price feed triggered the abnormal liquidation of 47 positions holding $3 million in collateral on Sept. 4.

Summary

  • 47 Vesu positions were liquidated across several pools during a two-minute oracle failure.
  • $3 million in collateral was affected before the Pragma price feed corrected itself.
  • Vesu said its contracts worked as programmed and contained no protocol vulnerability.
  • Vesu and other Starknet organizations are trying to recover funds for affected users.

Vesu traces $3M liquidation to Pragma price feed

Vesu said in a Sept. 5 incident disclosure that the liquidations occurred between 04:08 and 04:10 UTC on Sept. 4 after an upstream price source operated by Pragma supplied incorrect data.

During the two-minute incident, the faulty prices reached several Vesu liquidity pools and made 47 borrowing positions appear eligible for liquidation. Automated liquidators then removed approximately $3 million in collateral before the feed returned to the correct value.

According to the protocol, the price source corrected itself within two minutes and has operated normally since then. Vesu did not identify the affected assets or provide a pool-by-pool breakdown in its initial statement.

The company also did not disclose how far the incorrect prices differed from market rates, the amount of debt attached to the liquidated positions, or how much collateral liquidators retained. A technical report covering the incident is expected to provide more information about the affected markets and the sequence of on-chain transactions.

Pragma has since worked with the relevant organizations to deploy a fix addressing the source of the error, Vesu said. Liquidity pool curators suspended affected pools as a precaution, with Vesu expecting them to remove the restrictions after reviewing the fix.

Because Vesu uses isolated and curated lending pools, decisions on reopening individual markets rest with their curators. The initial update did not identify which curators had paused their pools or provide an exact timetable for restoring normal activity.

Vesu says its contracts contained no vulnerability

Separating the incident from a smart contract exploit, Vesu said its contracts were “operating as designed” and did not contain a vulnerability. The protocol added that it had no contract patch to deploy because the liquidation engine responded to the prices it received.

In an overcollateralized lending market, a borrower deposits assets worth more than the value of a loan. The protocol uses an external price feed to measure the collateral ratio, and a liquidation may begin when that ratio falls below the pool’s required level.

Vesu attributed the Sept. 4 liquidations to bad inputs rather than faulty execution. Under its account, the contracts received incorrect collateral prices and processed the affected positions according to the rules already written into the protocol.

A July 2026 liquidation risk explainer from crypto.news described price data as the central input used to calculate a DeFi loan’s health factor. The report noted that stale or manipulated data can liquidate a healthy position or prevent an unsafe one from being closed.

Oracle dependence also extends beyond lending markets. An August 2026 report on blockchain oracles explained that smart contracts cannot independently read off-chain market prices, leaving them reliant on outside systems that collect, combine and publish data on-chain.

According to that report, an oracle normally handles data sourcing, aggregation, and on-chain delivery. A failure at any of the three stages can pass an inaccurate value to an otherwise functional smart contract, which may then complete a trade or liquidation based on the faulty input.

Recovery talks involve Starknet organizations

Following the incident, Vesu said it began coordinating with Pragma, StarkWare, the Starknet Foundation, and the curators of the affected pools to recover funds collected through the liquidations.

The protocol has not yet explained how the recovery process will operate, how much of the $3 million remains recoverable, or whether liquidators have agreed to return any assets. Its statement also stopped short of announcing a guaranteed reimbursement amount or payment date.

For users with deposits in Vesu’s Earn product, the protocol advised keeping their positions open. Closing an Earn position before the recovery process is complete may remove the user’s eligibility for a refund, according to Vesu.

Borrowers whose positions were liquidated during the two-minute window were asked to open a support ticket through Vesu’s Discord server. The protocol did not specify what records users must submit, though wallet addresses and transaction details can identify affected positions on-chain.

Vesu’s response differs from an automatic reversal because blockchain transactions generally remain final after confirmation. Any restoration would therefore require recovered assets, voluntary returns from liquidators, protocol-controlled funds, or another compensation arrangement agreed upon by the parties. Vesu has not said which route it plans to use.

A comparable oracle-related event occurred on Aave in March 2026, when a stale parameter caused an estimated $26 million to $27 million in unintended wstETH liquidations. An August 2026 review of the incident reported that Aave later examined oracle update rates and fallback systems while using several oracle sources for major collateral types.

Vesu has not announced comparable changes to its oracle structure. Pragma’s root-cause fix was the only technical measure confirmed in the initial disclosure.

US users depend on Vesu’s recovery process

For users in the United States, the incident involves a permissionless DeFi product rather than an insured bank account. The SEC’s Investor.gov website states that the FDIC insures deposits at eligible banks but does not protect securities or similar investments against a decline in value.

Vesu did not point to any government-backed protection for affected users. Instead, it directed them to its own support process and said the organizations involved were working to recover the collateral taken during the abnormal liquidations.

The protocol has not disclosed whether it restricts recovery by nationality or residence. Its instructions apply to users whose positions were liquidated during the identified window and to Earn depositors seeking to preserve possible refund eligibility.

At the network level, Vesu forms part of Starknet’s DeFi infrastructure. Starknet identified the lender as one of the protocols supporting its STRK20 privacy rollout in June 2026, alongside decentralized exchanges avnu and Ekubo and staking provider Endur.

Vesu said it will publish a complete technical report after its investigation, while affected borrowers can submit Discord support tickets, and Earn users have been told not to close their positions.




Source link

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button