Ostium, a decentralized perpetuals platform for real-world assets on Arbitrum, was hit by an exploit that drained nearly $18 million in USDC from its main liquidity vault, according to blockchain security reporting and on-chain data. The incident is being investigated, with the loss tied to a compromised oracle signer private key that allegedly allowed attackers to manipulate pricing inputs and extract funds through repeated trades.
How the exploit allegedly worked
According to the source report, the attacker gained access to an oracle signer private key and used that access to get around verification checks built into the protocol. With those checks bypassed, the attacker was able to submit authorized oracle reports containing favorable future prices.
The report says the exploit relied on a registered PriceUpKeep forwarder and future-dated price data. That combination allegedly let the attacker create artificial profits rather than taking real market risk. Instead of depending on legitimate price movement, the attacker appears to have fed the system data that made a series of trades immediately profitable.
Looped trades drained the vault
On-chain analysis cited in the report indicates that the attacker carried out around 20 looped trades through delegated actions. The pattern involved opening and closing positions in rapid succession, allowing the attacker to profit at the protocol’s expense.
Those repeated loops pulled funds from Ostium’s main liquidity vault. Estimates in the source place the extracted amount in a range of roughly $11.86 million to nearly $18 million USDC. At the upper end, that would represent about 32% to 35% of the protocol’s roughly $34 million total value locked at the time of the exploit.
A primary exploit transaction is said to be publicly visible on Arbiscan, providing an on-chain record of the attack path and the movement of funds.
Project background and exposure
Ostium operates as a perpetuals exchange centered on real-world assets, a segment of decentralized finance that depends heavily on reliable external data feeds. That reliance appears central to this incident, since the reported point of failure was not ordinary market trading but the compromise of an oracle-related signing key.
The source article says the project had raised about $27.8 million from investors before the breach. The exploit therefore lands as a major security event for a relatively well-funded protocol in a fast-growing corner of DeFi.
Investigation under way
The incident remains under active investigation. No final accounting or recovery outcome was reported in the source, and the exact loss figure remains presented as an estimate based on observed on-chain activity.
The episode adds to broader concerns around oracle design, private-key security, and monitoring systems in DeFi applications that combine on-chain trading with off-chain data inputs. In Ostium’s case, the reported use of an authorized signer and registered forwarding infrastructure suggests the attacker exploited trusted components rather than a simple user-facing flaw.
The breach is also a reminder that oracle-dependent infrastructure can create concentrated operational risk, particularly for protocols handling synthetic or real-world asset exposure through perpetual trading products.
Source: beincrypto.com