A cybersecurity-themed illustration showing the Ostium logo, a broken oracle data feed, and a falling cryptocurrency chart representing the $18 million loss after the exploit.

Ostium loses $18M after Oracle exploit halts trading

Decentralised trading platform Ostium has paused all trading after an attacker exploited its oracle infrastructure and drained about $18 million from the protocol’s liquidity vault on Arbitrum.

The incident was first flagged by blockchain security firms Blockaid and CertiK, which said the attacker manipulated Ostium’s price reporting system to generate artificial trading profits before withdrawing funds from the protocol. Following the attack, Ostium suspended trading and launched an investigation while advising users to revoke contract approvals as a precaution.

Ostium is a decentralised perpetual futures exchange that allows users to trade cryptocurrencies as well as tokenised real-world assets such as stocks, commodities, indices and foreign exchange markets directly from a crypto wallet. The protocol relies on price oracles to feed external market prices onto the blockchain so trades can be settled accurately.

According to preliminary findings shared by Blockaid, the attacker compromised an oracle signer key and submitted fraudulent, future-dated price reports that appeared legitimate to the protocol. Those manipulated prices allowed the attacker to open and close positions at artificial values, extracting roughly $18 million in USDC from Ostium’s liquidity provider vault. Security researchers stressed that the investigation is ongoing and the exact sequence of events is still being reviewed.

An oracle is a service that delivers real-world information, such as the price of Bitcoin or gold, to blockchain applications. Because blockchains cannot access external data on their own, decentralised finance (DeFi) protocols depend on oracles to execute trades, settle contracts and trigger liquidations. If an attacker can manipulate that data, the protocol may execute transactions based on false prices.

In Ostium’s case, investigators believe the attacker exploited the protocol’s oracle infrastructure rather than the blockchain itself or users’ wallets. The manipulated price feeds enabled profitable trades that would not have been possible under normal market conditions, allowing funds to be withdrawn directly from the liquidity pool.

Ostium said user trading positions remain frozen while the incident is investigated. The protocol has not yet confirmed the final amount lost or announced how affected liquidity providers will be compensated.

The attack adds to a growing list of oracle-related exploits targeting DeFi protocols. While smart contract vulnerabilities have historically been the primary source of losses, attackers are increasingly focusing on the external infrastructure that supplies critical market data. Security experts say these incidents highlight the importance of protecting oracle signer keys and strengthening the validation of off-chain price feeds.

For Ostium, the immediate priority is restoring the integrity of its trading infrastructure. Until the investigation is complete, trading will remain suspended as the team works with security researchers to determine the full scope of the exploit and prevent similar attacks in the future.

Read also: Revolut moves closer to launching crypto services in the UAE

Leave a Reply