Ostium perpetuals DEX on Arbitrum lost $18M via oracle signer key compromise and falsified price data submission.
Security & Exploits ·
Ostium, an Arbitrum-based perpetuals exchange trading real-world assets, lost approximately $18 million in USDC on July 15 when an attacker exploited its price-feed infrastructure. The hacker gained access to a registered PriceUpKeep forwarder component and submitted oracle price reports bearing future-dated timestamps, fabricating profitable trade positions that triggered a vault payout.
Ostium's price-feed system relies on Gelato, a third-party automation network, to push real-world asset prices onchain. The PriceUpKeep smart contract serves as the execution trigger for these price updates whenever a trade occurs. By manipulating both the timing and content of oracle data, the attacker bypassed the protocol's defense mechanisms, exploiting the same class of vulnerability—compromised keeper and oracle systems—that has recurred across DeFi platforms. A similar $6 million drain from Summer.fi occurred in the preceding week.
The protocol had raised $27.8 million in funding, including a $24 million Series A round, and had facilitated over $50 billion in cumulative trading volume before the incident. No details have emerged regarding whether the compromised signer key was recovered, how the attacker initially gained access, or what remediation steps Ostium has taken to prevent recurrence.