Ostium says its July exploit was caused by a compromise in off-chain infrastructure that let an attacker manipulate price reporting and extract 23.75 million USDC from the protocol’s OLP liquidity vault. The protocol said its investigation found no flaw in smart contract logic and no sign that governance multisigs were compromised.

How the exploit unfolded

According to Ostium’s post-incident findings, the breach began outside the protocol’s on-chain systems. The attacker is said to have used forwarder paths that were already recognized as valid by the protocol, allowing manipulated reports to pass through existing checks.

Ostium said the first step was a small test trade using a 100 USDC position. That transaction allegedly produced about 897.8 USDC in artificial profit. After that successful test, the attacker moved on to a larger batch of transactions, sending roughly 11.9 million USDC to a beneficiary wallet. The protocol said six more standalone exploit cycles followed, bringing total losses from the OLP vault to 23.75 million USDC.

What was and was not affected

The protocol said the losses were borne by the public OLP vault, which was used to back liquidity, while trader collateral was not affected. Ostium said user margin remained inside the protocol’s trading contracts rather than in the compromised liquidity pool.

In its account of the incident, the team stressed that the exploit did not stem from a bug in core contract code. It also said the investigation found no evidence that the multisigs responsible for protocol governance had been breached.

Response and return to trading

Ostium said its automated monitoring systems detected unusual activity before further withdrawals could occur. The protocol then halted trading while it investigated the attack and moved operations to a new production environment with updated security controls.

Trading resumed on July 23 after that migration was completed. Ostium also said it is still working on a separate recovery plan for liquidity providers affected by the losses and that more information will be released in a dedicated update.

Earlier analysis and broader implications

Ostium’s latest explanation aligns with an earlier analysis from Blockaid, which had concluded that compromised signing credentials allowed fraudulent price reports to pass the protocol’s verification process. In Blockaid’s account, the attacker repeatedly opened and closed positions through delegated actions after submitting favorable future-dated price reports, generating gains that were effectively paid out by the OLP vault.

Both accounts point to supporting oracle-related infrastructure, rather than the smart contracts themselves, as the central weakness in the incident. The case has added to scrutiny around the off-chain systems decentralized finance platforms depend on for external market data and transaction validation.

The exploit came only weeks after Ostium announced a partnership with Nasdaq in May, saying Nasdaq market data would support equity perpetual products on the platform. Around that time, Ostium also said it had processed more than $50 billion in cumulative trading volume. Before the exploit, the protocol had raised about $27.8 million from investors including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute and GSR.

Source: crypto.news