Ostium exploited for $23.75M after attackers compromised off-chain infrastructure to submit fake BTC-USD price reports.
Security & Exploits ·
On July 15, 2026, attackers compromised Ostium's off-chain infrastructure and submitted unauthorized BTC-USD price reports to extract 23,752,846 USDC from the platform's public OLP vault. The attacker executed eight trading transactions between 14:18:23 and 14:23:52 UTC, repeatedly opening and closing positions at artificially manipulated prices. According to Ostium's investigation, the breach did not stem from a smart-contract vulnerability or a compromise of protocol multisignatures; instead, the attacker gained unauthorized access to the off-chain price-reporting system and exploited forwarder paths that the protocol recognized at the time.
Ostium uses a pull-based price system for assets without native onchain prices—relying on off-chain sources to generate signed price reports submitted during trade execution. The attacker leveraged this architecture to tie invalid price reports to orders they created, generating profits extracted solely from the OLP vault while trader collateral remained intact. The platform's circuit breaker triggered twice and ultimately halted further withdrawals; automated monitoring detected the anomalous activity within minutes, and trading contracts were frozen by 15:14 UTC.
Ostium migrated to a new production environment with updated security controls and resumed trading on July 23, 2026. The platform is coordinating recovery efforts with Mandiant, SEAL 911, zeroShadow, Collisionless, law enforcement, and asset issuers, though the onchain tracing and a separate recovery plan for liquidity providers remain in progress.