
Ostium has concluded that its July exploit originated from compromised off-chain infrastructure rather than a flaw in its smart contracts, after an investigation found the attacker manipulated price reporting to drain 23.75 million USDC from the protocol’s liquidity vault.
Summary
- Ostium said its investigation found the July exploit originated from compromised off chain infrastructure rather than a flaw in its smart contracts.
- Fraudulent BTC USD price reports allowed the attacker to drain 23.75 million USDC from the protocol’s OLP liquidity vault.
- The protocol said automated monitoring detected the attack, trading resumed on July 23, and user collateral remained unaffected.
- A recovery plan for affected liquidity providers is being finalized and will be shared in a separate update.
According to Ostium’s post-mortem published on Wednesday, the attacker gained unauthorized access to the protocol’s off-chain infrastructure and used it to submit fraudulent BTC-USD price reports.
The manipulated reports allowed the attacker to create artificial trading profits at the expense of the public OLP vault, while the protocol found no evidence that its smart contracts or governance multisigs had been compromised.
Ostium says exploit bypassed off-chain systems
During its investigation, Ostium said the initial breach occurred outside the protocol’s on-chain infrastructure. The team stated that its findings did not identify any vulnerability in the protocol’s smart contract logic or any compromise involving the multisigs responsible for governing the protocol.
Instead, the attacker abused forwarder paths that the protocol already recognized as valid. Ostium explained that the exploit began with a small test transaction involving a 100 USDC position, producing roughly 897.8 USDC in artificial profit before the attacker expanded the operation.
Following the successful test, the attacker executed the primary batch of transactions, transferring about 11.9 million USDC to a beneficiary wallet. Ostium said six additional standalone exploit cycles followed, bringing the total loss from the OLP vault to 23.75 million USDC.
Earlier reporting from blockchain security firm Blockaid had attributed the incident to a compromised oracle signer private key, saying the attacker bypassed the protocol’s price verification process by submitting manipulated price reports through a registered PriceUpKeep forwarder. At the time, Blockaid estimated that between $11.86 million and $18 million USDC had been withdrawn during approximately 20 trading loops, based on the exploit activity visible on-chain while the attack was still unfolding.
Automated monitoring limited additional losses
While the exploit succeeded in draining funds from the liquidity vault, Ostium said its automated monitoring systems detected the abnormal activity before additional withdrawals could take place. The protocol subsequently halted trading while its investigation continued and has since migrated to a new production environment with updated security controls.
Trading resumed on July 23 after the migration was completed.
Ostium also said trader collateral remained unaffected throughout the incident because user margin stayed inside the protocol’s trading contracts rather than the compromised liquidity pool.
The team added that it is still finalizing a separate recovery plan for liquidity providers whose funds were affected by the exploit. According to the protocol, further details will be released in a dedicated update.
Oracle infrastructure remained central to the attack
Although Ostium’s latest report attributes the incident to unauthorized access to its off-chain infrastructure, its findings are consistent with the attack path previously outlined by Blockaid, which concluded that compromised signing credentials allowed fraudulent price reports to pass the protocol’s verification process.
According to Blockaid’s earlier analysis, the attacker repeatedly opened and closed positions through delegated actions after submitting favorable future-dated price reports. Because the manipulated reports appeared valid to the protocol, each trading cycle generated profits for the attacker while transferring losses to the OLP liquidity vault instead of relying on a vulnerability in the smart contract code itself.
The incident has drawn attention to the security of supporting infrastructure that decentralized finance protocols rely on for external market data. In Ostium’s case, both the protocol’s post-mortem and Blockaid’s earlier investigation concluded that the exploit did not originate from flaws in the core smart contracts.
Ostium exploit followed Nasdaq partnership
The exploit occurred only weeks after Ostium expanded its institutional presence through a partnership with Nasdaq announced in May. At the time, the protocol said Nasdaq’s market data would support equity perpetual products listed on the platform.
Ostium also disclosed during that announcement that it had processed more than $50 billion in cumulative trading volume.
Before the exploit, the protocol had raised approximately $27.8 million from investors including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute and GSR, according to previous company disclosures.
