Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
→
Cluster
mainnet-beta
Slot
453401572
Off-chain at
2026-10-04T23:17:01.375Z
Anchored at
2026-10-04T23:17:04.550Z
Block time
—

Independent verification

1. Database (off-chain)
iShHXM2ZtmRSf5vQmAguC7k4CxrVmyhXofe8e3PoYPU
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (16221 chars)
{"actor":"system:backfill","investigation_id":"247c355e-1ef8-4e1d-abb9-8f99f961ab83","kind":"publish","page_slug":"vesu-protocol-pragma-oracle-malfunction-september-2026","published_at":"2026-10-04T23:17:01.309Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Vesu Protocol (Pragma Oracle Malfunction — September 2026)","sections":[{"content":"At approximately 04:08 UTC on September 4, 2026, Vesu — a non-custodial lending protocol deployed on Starknet — began processing liquidations triggered by corrupted price data from Pragma, its upstream oracle provider. Over a 108-second window ending at 04:10:04 UTC, 47 borrowing positions across 42 distinct wallets and seven liquidity pools were liquidated. Total collateral seized across the incident amounted to approximately $3,077,500. Borrower equity lost was approximately $783,905, and bad debt absorbed by the affected pools reached approximately $618,884. Vesu's protocol team stated that its smart contracts operated as designed and contained no exploitable vulnerability; the liquidations were a correct mechanical response to the incorrect pricing inputs Vesu received from Pragma.","heading":"Incident Overview","severity":"high","sources":[{"credibility":1,"name":"4 September oracle incident: post-mortem and updates — Pragma","type":"official","url":"https://www.pragma.build/updates/vesu-incident"},{"credibility":2,"name":"Vesu oracle incident triggers $3M in liquidations — Crypto.news","type":"news_article","url":"https://crypto.news/vesu-oracle-incident-triggers-3m-in-liquidations/"},{"credibility":1,"name":"How refunds from the 4 September incident will work — Vesu Security Council","type":"official","url":"https://docs.vesu.xyz/blog/2026-09-13-incident-refunds"}]},{"content":"Pragma's post-mortem identified a token-mapping error in its publisher SDK's asset registry as the root cause. The registry incorrectly mapped USDC to the legacy bridged USDC.e token rather than native USDC. This caused the SDK's price calculation to route through an inactive USDC.e/USDT pool on Ekubo, which produced a stale USDT/USD observation of approximately $3.07 — more than three times the correct value. At 04:07:52 UTC, three healthy USDT/USD source observations fell outside the oracle's 60-minute freshness window simultaneously, leaving only two observations: Bitstamp at approximately $0.99995 and the faulty Ekubo-derived value at $3.073203. With only two data points, the median calculation returned their average: $2.036576. The publisher SDK then used this figure as a USDT/USD conversion factor, dividing USDT-quoted venue prices for BTC, WBTC, ETH, STRK, and USDC by approximately 2.037, making those assets appear to have lost roughly half their market value. The wstETH/USD derived feed was also affected on a separate update cadence. Pragma stated: 'This was a failure in our pricing system. The affected users relied on data we provided, and we are sorry for the harm this caused.'","heading":"Root Cause: Pragma Oracle Pipeline Failure","severity":"high","sources":[{"credibility":1,"name":"4 September oracle incident: post-mortem and updates — Pragma","type":"official","url":"https://www.pragma.build/updates/vesu-incident"},{"credibility":2,"name":"Vesu Protocol Faces $3M in Erroneous Liquidations Due to Oracle Malfunction — Parameter","type":"news_article","url":"https://parameter.io/vesu-protocol-faces-3m-in-erroneous-liquidations-due-to-oracle-malfunction/"}]},{"content":"On September 7, 2026, the principal liquidator voluntarily returned seized assets, less their liquidation reward and costs, to the Vesu Security Council multisig. This cooperative return was the foundation of the recovery effort. By September 13, 2026, asset recovery was declared complete. The Vesu Security Council, working with the Starknet Security Council, pool curators, and partners, reported recovering approximately 95% of lost value at September 13 prices, or approximately 93% measured at prices on the morning of the incident. Total assets recovered were stated as $1,330,278.93, with $1,324,085.08 distributable after conversion costs, against total claims of $1,395,300.76 from both lenders and borrowers. Refunds are administered by the curators of the affected pools: Vesu, Re7 Labs, and Clearstar. Three user categories were defined. Active lenders in affected markets require no action, as recovered funds automatically restore pool share value. Lenders who withdrew funds after the incident must contact their curator through Discord with account details. Liquidated borrowers receive a direct refund in their original collateral asset at approximately 95% of losses. An additional, separate BTCfi rewards compensation was also made available to borrowers for the period during which their positions were involuntarily closed, requiring no additional user action. Vesu and its curators warned affected users to ignore any unsolicited contacts requesting wallet connections or message signatures in connection with the refund process.","heading":"Recovery and Refund Process","severity":"medium","sources":[{"credibility":1,"name":"How refunds from the 4 September incident will work — Vesu Security Council","type":"official","url":"https://docs.vesu.xyz/blog/2026-09-13-incident-refunds"},{"credibility":1,"name":"4 September oracle incident: post-mortem and updates — Pragma","type":"official","url":"https://www.pragma.build/updates/vesu-incident"},{"credibility":2,"name":"$3 Million Wiped in Two Minutes: How a Bad Price Feed Blindsided Vesu Users — CoinCentral","type":"news_article","url":"https://coincentral.com/3-million-wiped-in-two-minutes-how-a-bad-price-feed-blindsided-vesu-users"}]},{"content":"Pragma deployed SDK version 2.13.1 at 07:59 UTC on September 4, 2026, fixing the USDT/USD conversion factor to 1.00 and removing the feedback mechanism that had allowed the erroneous on-chain USDT/USD median to be used as a conversion input for other feeds. On September 13, Pragma deployed additional monitoring corrections and verified fresh deviation calculations in production. Minimum source-count requirements for USDT/USDC feeds were strengthened to four sources. Pragma's multisig administration was migrated to a 3-of-5 multisig structure. Enhanced explorer visibility for price feed health was deployed. Pragma noted that accurate source-count reporting for composed prices remained a pending remediation priority as of the post-mortem publication. Vesu's pool curators suspended affected markets immediately after the incident as a precautionary measure pending review of Pragma's fix. The Starknet Security Council temporarily restricted six addresses associated with the incident as part of its standard governance response; all restrictions were subsequently lifted after the investigation concluded.","heading":"Remediation and Protocol Changes","severity":"medium","sources":[{"credibility":1,"name":"4 September oracle incident: post-mortem and updates — Pragma","type":"official","url":"https://www.pragma.build/updates/vesu-incident"},{"credibility":1,"name":"Vesu incident Note — Starknet Community Forum","type":"official","url":"https://community.starknet.io/t/vesu-incident-note/116353"}]},{"content":"The Vesu/Pragma incident is distinct from a separate Starknet oracle-related event on September 17, 2026, in which Nostra Finance, a different Starknet lending protocol, suffered approximately $3.5 million in losses. According to reporting on the Nostra incident, an attacker allegedly manipulated the market price of Nostra's native NSTR token approximately 8,000-fold and used the inflated collateral to borrow liquid assets. That incident involved deliberate external price manipulation and a suspected exploiter rather than an upstream data-pipeline malfunction. The two events are separate, involve different protocols and different mechanisms, and should not be conflated.","heading":"Distinction from September 17 Nostra Finance Incident","severity":"low","sources":[{"credibility":2,"name":"Nostra Finance $3.5M Oracle Exploit Explained [2026] — Shattered.io","type":"news_article","url":"https://shattered.io/nostra-finance-3-5-million-pragma-oracle-exploit-2026/"},{"credibility":2,"name":"Nostra Halts Its Starknet Money Market After a $3.5M NSTR Oracle Exploit — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/18/nostra-halts-starknet-money-market-after-3-5m-nstr-oracle-exploit/"}]},{"content":"The incident illustrates a systemic risk common to DeFi lending protocols: a protocol's automated liquidation engine will execute correctly on incorrect inputs, with no on-chain mechanism to distinguish corrupted oracle data from genuine market moves. Vesu had no independent circuit breaker capable of detecting the two-minute price anomaly before liquidations executed. The absence of a minimum-source freshness floor on USDT/USD — which allowed the Ekubo stale observation to form 50% of the median — was the specific technical gap Pragma's remediation addressed. A comparable upstream oracle failure occurred in Aave in March 2026, reportedly resulting in approximately $26-27 million in unintended wstETH liquidations, suggesting this class of risk is not unique to Starknet or Pragma.","heading":"Oracle Dependency Risk","severity":"medium","sources":[{"credibility":1,"name":"4 September oracle incident: post-mortem and updates — Pragma","type":"official","url":"https://www.pragma.build/updates/vesu-incident"},{"credibility":2,"name":"$3 Million Wiped in Two Minutes: How a Bad Price Feed Blindsided Vesu Users — CoinCentral","type":"news_article","url":"https://coincentral.com/3-million-wiped-in-two-minutes-how-a-bad-price-feed-blindsided-vesu-users"}]}],"sources_used":[{"credibility":1,"name":"4 September oracle incident: post-mortem and updates — Pragma","type":"official","url":"https://www.pragma.build/updates/vesu-incident"},{"credibility":1,"name":"How refunds from the 4 September incident will work — Vesu Security Council","type":"official","url":"https://docs.vesu.xyz/blog/2026-09-13-incident-refunds"},{"credibility":1,"name":"Vesu incident Note — Starknet Community Forum","type":"official","url":"https://community.starknet.io/t/vesu-incident-note/116353"},{"credibility":2,"name":"Vesu oracle incident triggers $3M in liquidations — Crypto.news","type":"news_article","url":"https://crypto.news/vesu-oracle-incident-triggers-3m-in-liquidations/"},{"credibility":2,"name":"Vesu Oracle Incident Triggers $3M Liquidations on Starknet — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/09/05/vesu-oracle-incident-liquidations/"},{"credibility":2,"name":"Vesu Protocol Faces $3M in Erroneous Liquidations Due to Oracle Malfunction — Parameter","type":"news_article","url":"https://parameter.io/vesu-protocol-faces-3m-in-erroneous-liquidations-due-to-oracle-malfunction/"},{"credibility":2,"name":"Vesu Protocol Faces $3M Liquidation Crisis After Pragma Oracle Malfunction — Blockonomi","type":"news_article","url":"https://blockonomi.com/vesu-protocol-faces-3m-liquidation-crisis-after-pragma-oracle-malfunction"},{"credibility":2,"name":"$3 Million Wiped in Two Minutes: How a Bad Price Feed Blindsided Vesu Users — CoinCentral","type":"news_article","url":"https://coincentral.com/3-million-wiped-in-two-minutes-how-a-bad-price-feed-blindsided-vesu-users"},{"credibility":2,"name":"Nostra Finance $3.5M Oracle Exploit Explained [2026] — Shattered.io","type":"news_article","url":"https://shattered.io/nostra-finance-3-5-million-pragma-oracle-exploit-2026/"},{"credibility":2,"name":"Nostra Halts Its Starknet Money Market After a $3.5M NSTR Oracle Exploit — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/18/nostra-halts-starknet-money-market-after-3-5m-nstr-oracle-exploit/"}],"summary":"On September 4, 2026, Starknet lending protocol Vesu suffered approximately $3 million in erroneous liquidations after Pragma's oracle publishing pipeline delivered corrupted price data for roughly two minutes. Vesu's own smart contracts functioned as designed; the root cause was an upstream token-mapping error in Pragma's asset registry that caused major asset prices to appear at roughly half their true market value. By September 13, 2026, approximately 95% of lost value had been recovered and a structured refund process was underway, with three pool curators administering distributions to affected users.","timeline":[{"date":"2026-09-04","event":"At 04:07:52 UTC, an incorrect USDT/USD aggregate becomes active in Pragma's publishing pipeline after three healthy source observations fall outside the 60-minute freshness window simultaneously, leaving only a Bitstamp observation and a stale Ekubo-derived value to form the median.","source":"Pragma post-mortem","source_url":"https://www.pragma.build/updates/vesu-incident"},{"date":"2026-09-04","event":"At 04:08:14 UTC, the conversion error propagates to BTC, ETH, WBTC, STRK, and USDC price feeds, making those assets appear to be valued at roughly half their true market price.","source":"Pragma post-mortem","source_url":"https://www.pragma.build/updates/vesu-incident"},{"date":"2026-09-04","event":"Between 04:08:16 and 04:10:04 UTC, Vesu's automated liquidation engine executes 47 liquidations across 42 borrower wallets and seven pools, seizing approximately $3,077,500 in collateral.","source":"Pragma post-mortem / Vesu Security Council refund post","source_url":"https://www.pragma.build/updates/vesu-incident"},{"date":"2026-09-04","event":"At approximately 04:40 UTC, Pragma's price feeds normalize without manual intervention.","source":"Pragma post-mortem","source_url":"https://www.pragma.build/updates/vesu-incident"},{"date":"2026-09-04","event":"At 07:59 UTC, Pragma deploys SDK version 2.13.1, fixing the USDT/USD conversion factor to 1.00 and removing the feedback mechanism that allowed the erroneous on-chain median to propagate to other feeds.","source":"Pragma post-mortem","source_url":"https://www.pragma.build/updates/vesu-incident"},{"date":"2026-09-04","event":"Vesu pool curators suspend affected markets pending review of Pragma's fix. Vesu states its smart contracts operated as designed and contained no vulnerability.","source":"Crypto.news","source_url":"https://crypto.news/vesu-oracle-incident-triggers-3m-in-liquidations/"},{"date":"2026-09-05","event":"Multiple crypto news outlets publish initial coverage of the incident. Vesu directs affected users to open Discord support tickets. Earn product users are warned not to close positions prematurely to preserve refund eligibility.","source":"Cryptonomist / Crypto.news","source_url":"https://en.cryptonomist.ch/2026/09/05/vesu-oracle-incident-liquidations/"},{"date":"2026-09-07","event":"The principal liquidator cooperatively returns seized assets, less liquidation costs and reward, to the Vesu Security Council multisig. Recovery funds are confirmed in the multisig.","source":"Pragma post-mortem","source_url":"https://www.pragma.build/updates/vesu-incident"},{"date":"2026-09-13","event":"Asset recovery is declared complete. Vesu Security Council publishes the refund structure: 95% recovery at current prices across three user categories, administered by curators Vesu, Re7 Labs, and Clearstar. Pragma deploys additional monitoring corrections.","source":"Vesu Security Council refund post","source_url":"https://docs.vesu.xyz/blog/2026-09-13-incident-refunds"},{"date":"2026-09-15","event":"Pragma begins deploying SDK improvements and Foundation publisher activation as part of its remediation roadmap. Multisig migration to 3-of-5 structure is initiated.","source":"Pragma post-mortem","source_url":"https://www.pragma.build/updates/vesu-incident"},{"date":"2026-09-17","event":"Separate incident: Nostra Finance, a different Starknet lending protocol, reportedly suffers approximately $3.5 million in losses due to alleged deliberate price manipulation of its NSTR token. This event is unrelated to the Vesu/Pragma pipeline failure of September 4.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/09/18/nostra-halts-starknet-money-market-after-3-5m-nstr-oracle-exploit/"}]},"v":1}