Ostium has suspended trading after an attacker allegedly used a compromised oracle signer key to extract between $11.86 million and nearly $18 million USDC from the protocol’s liquidity vault, according to blockchain security firm Blockaid.

How the attack was carried out

Blockaid said the incident was not caused by a flaw in Ostium’s smart contract code. Instead, the attacker is reported to have obtained control of an oracle signer private key, which let them get around the protocol’s verification flow and submit future-dated price reports that benefited their own positions.

Because the reports appeared valid to the system, the attacker was able to make trades that looked legitimate on-chain while shifting losses to Ostium’s main liquidity vault. Blockaid said the manipulated oracle data effectively allowed the attacker to profit without taking real market risk.

Repeated trading loops drained the vault

According to Blockaid, the attacker used a registered PriceUpKeep forwarder to repeatedly open and close positions through delegated actions. The firm said this process was executed in around 20 trading loops.

Those repeated transactions steadily pulled funds from the vault. On-chain records cited in the report show withdrawals totaling between $11.86 million and $18 million USDC. At the upper end of that range, the losses would represent roughly 28% of Ostium’s $63 million total value locked at the time of the exploit. Blockaid also said the main exploit transaction can be viewed on Arbiscan.

Protocol response and investigation

Following the incident, Ostium halted trading while the attack is investigated. The protocol, which runs on Arbitrum, offers decentralized perpetual trading tied to tokenized real-world assets, including equities, commodities, foreign exchange markets and stock indices.

Blockaid attributed the event to compromised signing credentials rather than a pricing error or market manipulation carried out through ordinary trading activity. Users have been directed to Ostium’s official communication channels for updates on withdrawals and any possible recovery steps as the investigation continues.

Broader security questions

The exploit has renewed scrutiny of oracle security in decentralized finance, where protocols depend on external data feeds to determine prices. The case also underlines that a project can face major losses even when the underlying issue lies outside audited smart contract logic.

Before the incident, Ostium had raised about $27.8 million from backers including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute and GSR. The attack took place despite that institutional support and multiple security audits, adding to concerns that trusted infrastructure such as signing systems can become a critical point of failure.

Source: crypto.news