Ostium launches two-stage recovery plan after $23.75M exploit, offering 100% loss recovery for smaller claims in stage one.
Security & Exploits ·
A July 15 attack on Ostium's pricing and signing systems resulted in approximately $23.75 million withdrawn from the Ostium Liquidity Pool, with evidence pointing to a state actor. Trading resumed on July 23 after infrastructure migration and hardening. A small recovery of 649,967 USDC has been obtained so far, with ongoing efforts involving investigators, law enforcement, and exchanges to recover additional funds.
Ostium has deployed a two-part recovery framework accessible via a Recovery Portal. Stage 1 targets 3,321 affected wallets (90.59 percent of 3,666 total impacted accounts) with immediate 100 percent loss recovery: Group A, covering losses of 1,000 USDC or less, provides equal USDC from a Convenience Contract through December 29, 2026; Group B, for larger losses, offers either a fixed 1,000 USDC payment or deferral to Stage 2, with elections due by October 30, 2026. Stage 2 will distribute unclaimed Group funds, fresh recoveries from the attacker, and a dedicated share of protocol revenues on a pro-rata basis to participants who defer.
The remaining affected wallets retain a pro-rata stake in vault assets currently valued at roughly 30 percent of pre-incident holdings. Settlement operations resumed on a regular weekday cadence in September, though new deposits remain suspended. Further details on Stage 2 mechanics, protocol revenue allocation, and company operations are expected before the October 30 deadline.