EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Uncovering the Ostium loophole: How fake prices could leverage a $23.75 million robbery

2026-07-19 12:16:15
Bookmark

The Ostium protocol was attacked and 23.75 million USDC were stolen.

The oracle credentials were breached, resulting in false market prices being checked by the Ostium verifier and treated as legitimate reports. Eight payments to the same wallet ultimately confirmed the agreement that OLP Treasury lost 23,752,746 USDC. Traders 'collateral remains quarantined, but open positions remain frozen until preparations for a safe restart are in place. Most of the stolen USDC were exchanged for 12,084 ETH and then flowed into Tornado Cash, making money recovery more difficult.

Ostium has confirmed that a security breach occurred on July 15 resulted in the theft of 23,752,746 USDC from the vault of the protocol's liquidity provider. According to the report, the attacker breached offline pricing infrastructure and submitted false reports that appeared to the platform to be legitimate.

Incident

On July 15, Ostium's LP (Liquidity Provider) vault was attacked and 23,752,746 USDC were lost. Based on ongoing investigations, the attacker breached the off-chain infrastructure associated with the protocol price entry system. These reports allow traders to open and close positions at fictitious profits, all paid out of the Ostium liquidity pool. Trading is still on hold, and the Arbitrum-based platform is strengthening security measures and preparing to restart.

How a compromised certificate converts false prices into USDC

Ostium offers perpetual contracts related to stocks, commodities, currencies, indices and cryptocurrencies, with transactions settled in USDC through the Arbitrum network. To support these markets, external systems provide prices for opening positions, closing positions, clearing and profit calculations. At the same time, liquidity providers deposit USDC into OLP vaults, which are used to pay for positions of profitable traders. As a result, when false proceeds pass through the agreed settlement process, the vault becomes a source of compensation.

Galaxy Research tracked eight payments flowing into the same wallet, including transfers worth approximately $11.86 million,$4.49 million and $3.59 million. There were also $2.7 million and $1.08 million in payouts, ultimately bringing Ostium's confirmed loss to nearly $23.75 million. However, the attack did not stem from market fluctuations or a direct failure of core trading contracts. Instead, the attacker obtained credentials related to two privileged components in the platform's pricing system.

According to Galaxy, Ostium's validator checks whether each price report carries a signature from the authorized oracle signer. However, the system does not independently confirm whether the prices submitted accurately reflect broader market conditions. According to reports, the attacker took control of both an authorized signer certificate and a registered PriceUpKeep transponder. With these authorities, price reports on future dates can pass protocol checks, and subsequent repeated position cycles generate false gains.

So contracts continue to operate according to the rules they set, but they rely on tampered data. In fact, legal certificates make false market information seem real and effective, thereby transforming artificially manipulated prices into real USDC claims.

Transactions are frozen, investigators track capital flows

Although the liquidity vault suffered significant losses, Ostium said traders 'collateral was protected in a separate, segregated contract. Open positions remain frozen and users cannot adjust their margins during the system shutdown. When trading finally resumes, the agreement will use the price at the time of the re-opening to evaluate the position, rather than the price recorded during the suspension. This approach can reduce the impact of market fluctuations that traders cannot cope with due to platform unavailability.

Ostium said that within 60 minutes of the first malicious transaction, they suspended the transaction and froze the relevant contract. Since then, the platform has been working with Mandiant, zeroShadow, Collisionless, SEAL 911, law enforcement, exchanges, cross-chain bridges and stablecoin issuers. At the same time, investigators continue to track stolen assets and review the infrastructure needed for a safe restart. Ostium also promises to notify users at least 24 hours in advance before trading contracts are reopened.

However, these funds have been transferred multiple times. Lookonchain reported that the attackers exchanged 23.75 million USDC for approximately 12,084 ETH units, with an average price of approximately $1,966. Subsequently, most of the ether flowed into Tornado Cash, blurring the correlation between deposits and subsequent withdrawals. As a result, recovering stolen assets has become more difficult for investigators and participating service providers.

The attack affected a platform with cumulative transaction volume exceeding US$50 billion in 75 supported markets. Ostium also raised $24 million in December 2025, bringing its total disclosed funding to $27.8 million.

In the final analysis, this incident shows how compromised off-chain infrastructure can weaken otherwise functioning on-chain contracts. As a result, Ostium's recovery will depend on stricter credential controls, independent price verification, and tighter operational security safeguards.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP