Onchain perpetuals exchange Ostium concluded that a July 15 exploit draining 23.75 million USDC from its OLP liquidity vault stemmed from compromised off-chain infrastructure, not a flaw in its smart contracts.
"Based on our investigation, we have no evidence this incident was a result of a vulnerability in Ostium's smart-contract code logic or a compromise of the multisigs that govern the protocol," the team said in a post-mortem published Wednesday.
The attacker gained unauthorized access to Ostium's off-chain systems and submitted fraudulent BTC-USD price reports, according to the protocol. A test transaction using a 100 USDC position generated roughly 897.8 USDC in artificial profit before the attacker scaled up. The main batch transferred 11.9 million USDC to a beneficiary wallet, followed by six additional exploit cycles that brought the total loss to 23.75 million USDC from the OLP vault. Blockchain security firm Blockaid previously attributed the incident to a compromised oracle signer private key, saying the attacker bypassed price verification through a registered PriceUpKeep forwarder.
Ostium said its automated monitoring detected the abnormal activity and prevented further withdrawals. The protocol halted trading, migrated to a new production environment with updated security controls, and resumed trading on July 23. User collateral remained unaffected because margin stayed inside the protocol's trading contracts rather than the compromised liquidity pool. A separate recovery plan for affected liquidity providers is being finalized, the team added.
The exploit comes weeks after Ostium partnered with Nasdaq in May to power equity perpetual products using the exchange operator's market data. The protocol had processed more than $50 billion in cumulative trading volume and raised approximately $27.8 million from investors including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute and GSR. The incident highlights the security risks in off-chain oracle infrastructure that DeFi protocols rely on for external market data — a vulnerability that can bypass even sound smart contract logic.
This article is for informational purposes only and does not constitute investment advice.