Ostium concluded that its July exploit started in compromised off-chain infrastructure, not in its smart contract logic. Fraudulent BTC-USD price reports let the attacker drain 23.75 million USDC from the protocol's OLP liquidity vault. Trading resumed on July 23, and Ostium said trader collateral stayed untouched.
Ostium has concluded that its July exploit originated from compromised off-chain infrastructure rather than a flaw in its smart contracts, after an investigation found the attacker manipulated price reporting to drain 23.75 million USDC from the protocol's liquidity vault.
According to Ostium's post-mortem published on Wednesday, the attacker gained unauthorized access to the protocol's off-chain infrastructure and used it to submit fraudulent BTC-USD price reports. The manipulated reports created artificial trading profits at the expense of the public OLP vault, while the protocol found no evidence that its smart contracts or governance multisigs had been compromised.
Attack began with a 100 USDC test position
Instead of breaking the contract code, the attacker abused forwarder paths that the protocol already recognized as valid. Ostium said the exploit began with a small test transaction involving a 100 USDC position, producing roughly 897.8 USDC in artificial profit before the attacker expanded the operation.
Following the successful test, the attacker executed the primary batch of transactions, transferring about 11.9 million USDC to a beneficiary wallet. Ostium said six additional standalone exploit cycles followed, bringing the total loss from the OLP vault to 23.75 million USDC.
Automated monitoring limited additional losses
Ostium said its automated monitoring systems detected the abnormal activity before additional withdrawals could take place. The protocol then halted trading while its investigation continued and has since migrated to a new production environment with updated security controls. Trading resumed on July 23 after the migration was completed.
Trader collateral remained unaffected throughout the incident, according to Ostium, because user margin stayed inside the protocol's trading contracts rather than the compromised liquidity pool. The team added that it is still finalizing a separate recovery plan for liquidity providers whose funds the exploit affected, with further details to follow in a dedicated update.
Blockaid earlier traced the attack to a compromised signer key
Earlier reporting from blockchain security firm Blockaid had attributed the incident to a compromised oracle signer private key, saying the attacker bypassed the protocol's price verification process by submitting manipulated price reports through a registered PriceUpKeep forwarder. Blockaid estimated at the time that between $11.86 million and $18 million USDC had been withdrawn during approximately 20 trading loops, based on the exploit activity visible on-chain while the attack was still unfolding.
Ostium's findings are consistent with that attack path. Blockaid concluded that compromised signing credentials allowed fraudulent price reports to pass the protocol's verification process, with each trading cycle generating profits for the attacker while transferring losses to the OLP liquidity vault instead of relying on a vulnerability in the smart contract code itself.
Exploit followed Ostium's Nasdaq partnership
The breach came only weeks after Ostium expanded its institutional presence through a partnership with Nasdaq announced in May. At the time, the protocol said Nasdaq's market data would support equity perpetual products listed on the platform.
Ostium also disclosed during that announcement that it had processed more than $50 billion in cumulative trading volume. Before the exploit, the protocol had raised approximately $27.8 million from investors including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute and GSR, according to previous company disclosures.
Source: crypto.news
Trading involves risk.