Ostium has concluded that a July attack which stripped 23.75m USDC from its liquidity vault was carried out through compromised off-chain infrastructure, rather than any weakness in its smart contracts.
The decentralised trading protocol said in a detailed post-mortem that the attacker gained unauthorised access to its off-chain systems and then fed in falsified BTC-USD prices, allowing them to siphon funds from the public OLP vault.
According to Ostium, the manipulation enabled the attacker to engineer “artificial trading profits” for their own benefit, with the corresponding losses borne entirely by the OLP liquidity pool. The protocol stressed that it had found no evidence of its on-chain smart contract logic or governance multisig wallets being breached.
How the exploit unfolded
Investigators at Ostium traced the origin of the incident to infrastructure outside the blockchain, confirming that the initial break-in did not involve the protocol’s on-chain components.
Rather than introducing new or unauthorised routes, the attacker is said to have abused existing forwarder paths that the protocol already treated as valid. Ostium explained that the exploit began cautiously, with a test trade based on a 100 USDC position. That transaction generated around 897.8 USDC in bogus profit, effectively proving the method before the attacker scaled up.
Once that test succeeded, the attacker launched the main wave of transactions. In that phase, approximately 11.9m USDC was moved to a beneficiary wallet via the manipulated trading activity. Ostium added that this was followed by six further standalone exploit cycles, taking the total loss from the OLP vault to 23.75m USDC.
Earlier, blockchain security company Blockaid had attributed the incident to a compromised oracle signer private key. It reported that the attacker had been able to bypass Ostium’s price verification safeguards by pushing falsified price data through a registered PriceUpKeep forwarder.
At the time of Blockaid’s initial analysis, conducted while the attack was still playing out on-chain, the firm estimated that between 11.86m and 18m USDC had been withdrawn across roughly 20 trading loops.
Monitoring tools triggered as attack progressed
Ostium said its automated monitoring tools eventually detected the abnormal trading patterns, preventing even larger outflows from the liquidity vault.
In response, the protocol halted trading while it carried out a full investigation and rebuilt its set-up in a fresh production environment, adding what it described as enhanced security controls to the off-chain infrastructure.
Trading on the platform resumed on 23 July after that migration was completed.
Throughout the incident, Ostium said trader margin remained safe because user collateral is held inside the protocol’s trading contracts, separate from the OLP liquidity pool that was exploited. As a result, it said, collateral posted by traders was not directly affected by the breach.
The team added that it is still working on a dedicated recovery plan for liquidity providers whose capital was in the OLP vault at the time of the attack. Ostium has said more information on that programme will be issued in a separate update.
Findings line up with external security analysis
Although Ostium’s investigation emphasises unauthorised access to off-chain systems as the root cause, its conclusions align closely with the attack path previously mapped out by Blockaid.
Blockaid’s analysis suggested that compromised signing credentials allowed fraudulent price reports to pass the protocol’s own verification checks, because they appeared to come from legitimate sources. After submitting future-dated prices that were favourable to the attacker, the exploiter repeatedly opened and closed positions via delegated actions.
Each loop generated profit for the attacker and corresponding losses for the OLP liquidity vault, not by exploiting a bug in the smart contracts, but by feeding the system with corrupt external market data that it had no reason to distrust.
Both Ostium’s post-mortem and Blockaid’s work underline that the core on-chain contracts themselves did not contain the vulnerability that led to the loss.
Spotlight on DeFi infrastructure risks
The incident has intensified scrutiny on the broader infrastructure underpinning decentralised finance platforms, particularly the off-chain components and oracle systems used to import market data from traditional exchanges and data vendors.
In Ostium’s case, the breach came only weeks after the protocol announced in May that it was expanding its institutional footprint through a partnership with Nasdaq. At that time, Ostium said Nasdaq’s market data would underpin equity perpetual products available on its platform.
The same announcement revealed that Ostium had already processed more than $50bn in cumulative trading volume.
Prior to the exploit, the protocol had raised about $27.8m from backers including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute and GSR, according to its earlier disclosures.
