Ostium hacked on Arbitrum with estimated $18 million loss

Ostium hacked on Arbitrum with estimated $18 million loss

Ostium said a five-minute incident hit its public OLP vault, while security firms said authorized oracle reports enabled artificial profits and pushed loss estimates as high as about $24 million.

ETH
USDC
ARB

Fact Check
The originating source, the Blockaid detection post, directly confirms the exploit mechanism described in the claim: a registered PriceUpKeep forwarder and future-dated authorized oracle reports used to fabricate trade profit, draining ~$18M USDC from the Ostium Vault on Arbitrum. WuBlockchain, PANews, BlockBeats, and Odaily independently corroborate the same event, date (2026-07-15), platform, and mechanism. The ~$18M figure is the central estimate (Odaily notes a range of $12M-$18M, ~35% of the ~$34M vault). The claim's specifics align closely with the primary source, though loss figures remain estimates at time of reporting.
Summary

Ostium, an Arbitrum-based perpetuals platform for tokenized real-world assets, said a five-minute security incident on July 15, 2026 affected its public Ostium Liquidity Provider vault and led to losses, though it has not yet published a definitive total or root cause. Co-founder Kaledora Kiernan-Linn said the issue ran from 14:18 to 14:23 UTC, was identified within minutes, and led to a coordinated trading pause within the hour. Third-party security firms said the incident centered on authorized oracle data rather than a missing signature, with a registered PriceUpKeep forwarder allegedly submitting future-dated reports that created artificial trading profits paid from vault liquidity. Published estimates varied as tracing continued, from a visible 11,862,444.782 USDC outflow cited by SlowMist to roughly $18 million by Blockaid, $23.7 million by Cyvers and about $24 million by PeckShield. PeckShield said the extracted USDC was swapped into 12,080 ETH and that 10,540 ETH had reached Tornado Cash by its update. The episode has sharpened focus on oracle design because cryptographic authentication only shows an authorized key signed a report, while timestamp freshness, price plausibility and settlement safety require separate controls.

Terms & Concepts
  • PriceUpKeep forwarder: A registered mechanism used to relay authorized price update reports into a protocol.
  • ECDSA signer: A cryptographic signing identity used to prove that a message was authorized by a particular key.
  • Tornado Cash: A crypto mixing service used to make transaction flows harder to trace.