Key Takeaways
- Pragma’s defective oracle data led to the erroneous liquidation of 47 user positions on Vesu on September 4
- Approximately $3 million worth of user collateral was impacted during a 120-second period
- Vesu maintains that its protocol infrastructure functioned properly without any security flaws
- Pragma has implemented a corrective solution while impacted liquidity pools remain paused for safety
- Recovery coordination is underway between Vesu and multiple Starknet ecosystem partners
An oracle data malfunction on Starknet’s Vesu lending platform resulted in the improper liquidation of 47 borrowing positions totaling $3 million in user collateral on September 4, 2026.
The malfunction occurred within an extremely narrow timeframeābetween 04:08 and 04:10 UTCāyet managed to disrupt multiple liquidity pools on the platform.
Understanding the Technical Breakdown
Vesu relies on Pragma’s oracle infrastructure to track real-time asset valuations and assess the safety of user borrowing positions. When Pragma delivered erroneous pricing information, Vesu’s liquidation mechanism identified 47 positions as undercollateralized and vulnerable to liquidation.
Automated liquidation bots immediately seized roughly $3 million in user collateral before the oracle feed self-corrected. The pricing anomaly persisted for fewer than 120 seconds before normal market pricing resumed.
Vesu has not yet revealed which specific tokens were mispriced, the magnitude of the pricing deviation from actual market rates, or what portion of collateral was kept by liquidation participants. A comprehensive technical analysis is forthcoming.
Protocol Defends Smart Contract Integrity
Vesu emphasized that its underlying smart contract infrastructure was “functioning as intended” and free from security vulnerabilities. The team stated no code modifications were necessary since the liquidation system simply responded to flawed oracle inputs.
In overcollateralized lending protocols, users pledge assets exceeding their borrowed amounts. The system continuously monitors collateral-to-debt ratios using external price oracles. When a compromised oracle reports ratios falling below safety thresholds, automated liquidations trigger immediately.
Vesu characterized the September 4 incident as an input data problem rather than an execution or design flaw.
Fund Recovery Initiatives in Progress
After the incident, Vesu initiated collaboration with Pragma, StarkWare, the Starknet Foundation, and pool administrators to attempt fund retrieval for impacted users.
Vesu has not disclosed what percentage of the $3 million is recoverable or whether liquidation bot operators have committed to returning seized assets. No definitive compensation timeline or guaranteed refund amounts have been established.
Affected users were instructed to submit support requests through Vesu’s Discord channel. Those utilizing the Earn feature were cautioned against prematurely withdrawing funds, as doing so might jeopardize their eligibility for potential reimbursement.
Context Within DeFi Oracle Incidents
Oracle-related failures represent an ongoing challenge across decentralized finance. A comparable incident affected Aave in March 2026, where outdated configuration parameters resulted in approximately $26 to $27 million in unwarranted wstETH liquidations. Aave subsequently reassessed its oracle refresh intervals and contingency protocols.
Vesu has not disclosed plans to modify its oracle architecture beyond Pragma’s deployed remediation.
Smart contracts lack native capability to access external market data. They depend entirely on oracle networks to collect, verify, and transmit pricing information onto blockchain networks. Disruptions anywhere in this pipeline can trigger erroneous transactions or liquidations.
Vesu confirmed that a detailed technical postmortem will be published following their ongoing investigation.





