It took just two minutes for 47 borrowing positions on lending protocol Vesu to vanish. On Sept. 4, 2026, an abnormal liquidation wave liquidated $3 million worth of user collateral on the Starknet network due to incorrect price data. The series of forced closures occurred precisely between 04:08 and 04:10 UTC.
The incident began when the Pragma oracle supplied incorrect price feeds to several Vesu liquidity pools. The erroneous pricing led the system to read dozens of healthy loan positions as having breached their collateralization thresholds.
Automated liquidators immediately went to work executing millions of dollars in collateral. The Pragma team corrected their price data within the same 120-second window. As soon as the numbers returned to accurate levels, the entire system resumed normal operations.
Not a Smart Contract Code Flaw
Vesu’s development team emphasized that their smart contracts functioned exactly as designed. The morning incident was not a hacker exploit breaching protocol code security, but purely the result of bad raw data input.
Vesu has launched an intensive coordination process to handle the wave of improper liquidations. They are collaborating with teams from Pragma, StarkWare, the Starknet Foundation, and curators of the affected pools. The main objective of the talks is finding a solution to recover the $3 million in user funds.
Strict Conditions for Reimbursement Claims
Although negotiations are ongoing, the protocol has not yet detailed the recovery framework. They have not confirmed what percentage of assets can be reimbursed, or whether liquidators are willing to return the seized funds.
Vesu issued two separate instructions for its users. Borrowers whose collateral was liquidated in the 04:08 to 04:10 UTC window are asked to open a support ticket on the protocol’s official Discord channel immediately. Meanwhile, liquidity providers in Earn positions received a strict warning to keep their positions open. Closing positions before the remediation process is fully completed will void their eligibility for asset refunds.
Ecosystem Vulnerability
The Vesu incident once again highlights oracle dependency as a fundamental weakness in decentralized finance infrastructure. A similar situation hit lending platform Aave in March 2026, when stale price parameters triggered forced liquidations on wstETH tokens with losses ranging between $26 million and $27 million.
Skewed or manipulated data has proven capable of wiping out otherwise stable assets. No matter how well a smart contract is built, the system simply obeys incoming numbers from the oracle - regardless of whether that data is accurate or flawed. Reported by crypto.news.
Read also: What Is DeFi (Decentralized Finance)?
Read also: Tectonic Hit by $75M Exploit in 20 Minutes - But Oracle Provider Insists System Was Not Compromised
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




