Ostium vault drained of $11.86 million via compromised oracle key
Security & Exploits ·
An attacker exploited a compromised oracle signer on the Arbitrum-based perp/RWA protocol, siphoning nearly a third of the vault's holdings before trading was halted.
Ostium's OstiumVault, which backs the protocol's oLP token, lost approximately 11,862,445 USDC, or roughly $11.86 million, on July 15, 2026, according to defiprime.com. The stolen amount represents about 32% of the vault's $34.3M total value locked. The attacker's proceeds were sent to a wallet identified as 0x321df194, while the victim contract has been catalogued on arbiscan.io.
The mechanism centered on a privileged forwarder account that was also registered as an authorized oracle signer. Ostium's price-verification logic, OstiumVerifier.verify(), recovers the signer of a submitted price report and checks it against isAuthorizedSigner[signer], a mapping only governance can update; neither the forwarder role nor the signer role can be self-granted, indicating that an actual Ostium oracle or forwarder private key was compromised rather than a logic flaw being exploited. Using this authority, the attacker submitted self-signed, favorable price data and chained delegatedAction calls into openTrade and performUpkeep(closeTradeMarket), repeating the open-and-close cycle 20 times in rapid succession to lock in profit on each round-trip before draining the vault.
Coverage of the same incident elsewhere in the cluster describes the loss at a higher figure of roughly $18 million and cites the attacker posting a fake $5,000 Bitcoin price to trade against, suggesting reports may vary in scope or that additional funds were extracted beyond the initially confirmed $11.86 million. One account of the broader episode notes Ostium subsequently paused trading and that the attacker began converting stolen USDC into ETH and dispersing it across multiple wallets, a laundering pattern also referenced via wublockchain.xyz.
The episode has drawn coverage from at least ten distinct sources, with some accounts, including one shared on x.com, converging on the compromised-oracle-key narrative while diverging on the total dollar loss. Not yet confirmed is which specific key or signer was compromised, how the attacker obtained it, whether any funds can be recovered or frozen as they move through ETH conversions, and whether Ostium plans to resume trading or replace its oracle signer infrastructure.