Ostium Loses $23.7M After Off-Chain Price Oracle Breach, Recovers Trading Post-Migration

Ostium, an Arbitrum-based RWA buying and selling platform, suffered a serious safety breach on July 15 that resulted within the withdrawal of roughly 23.75 million USDC from its public liquidity supplier vault.
The assault compromised the protocol’s off-chain value infrastructure relatively than its on-chain sensible contracts or governance methods, highlighting how decentralized finance platforms stay weak to weaknesses in conventional IT infrastructure.
According to the corporate’s incident report printed on social media platform X, attackers exploited Ostium’s pull-based value settlement system, which depends on off-chain information sources to generate signed value studies for markets together with BTC-USD.
Having gained unauthorized entry to this infrastructure, the attackers submitted falsified studies displaying Bitcoin at $5,000 and $60,000—values far faraway from precise market charges. Between 14:18 and 14:23 UTC, they executed eight speedy open-and-close trades by official forwarder paths already acknowledged by the protocol.
By opening positions at one manipulated value and shutting them on the different inside atomic transactions, the attacker generated synthetic profit-and-loss calculations that compelled the OLP vault to pay out practically 24 million USDC in illegitimate earnings.
Ostium burdened that the incident didn’t stem from sensible contract logic flaws or compromised governance multi-signatures. Trader collateral remained safe in buying and selling contracts all through the incident, and no different consumer positions have been settled in opposition to the manipulated costs.
Swift On-Chain Containment and Migration to Hardened Infrastructure
Automated monitoring methods detected the anomalous exercise inside minutes, triggering vault circuit breakers that prevented further withdrawals. The workforce executed its first on-chain containment transaction at 14:55 UTC and froze all buying and selling contracts inside 20 minutes after the preliminary take a look at transaction.
In the aftermath, Ostium migrated to a brand new manufacturing setting that includes enhanced multi-party approval controls and resumed buying and selling on July 23. The stolen USDC was transformed to ETH and dispersed throughout a community of attacker-controlled wallets, with a considerable portion routed by Tornado Cash, complicating restoration efforts.
Ostium has retained cybersecurity companies Mandiant and SEAL 911, alongside blockchain intelligence specialists zeroShadow and Collisionless, to conduct forensic investigations and hint the funds.
The firm is actively coordinating with regulation enforcement, exchanges, and bridges to freeze belongings the place doable, and expects to publish a restoration plan for affected liquidity suppliers within the coming days.
The submit Ostium Loses $23.7M After Off-Chain Price Oracle Breach, Recovers Trading Post-Migration appeared first on Metaverse Post.
