
Ostium said a five-minute incident hit its public OLP vault, while security firms said authorized oracle reports enabled artificial profits and pushed loss estimates as high as about $24 million.
Ostium, an Arbitrum-based perpetuals platform for tokenized real-world assets, said a five-minute security incident on July 15, 2026 affected its public Ostium Liquidity Provider vault and led to losses, though it has not yet published a definitive total or root cause. Co-founder Kaledora Kiernan-Linn said the issue ran from 14:18 to 14:23 UTC, was identified within minutes, and led to a coordinated trading pause within the hour. Third-party security firms said the incident centered on authorized oracle data rather than a missing signature, with a registered PriceUpKeep forwarder allegedly submitting future-dated reports that created artificial trading profits paid from vault liquidity. Published estimates varied as tracing continued, from a visible 11,862,444.782 USDC outflow cited by SlowMist to roughly $18 million by Blockaid, $23.7 million by Cyvers and about $24 million by PeckShield. PeckShield said the extracted USDC was swapped into 12,080 ETH and that 10,540 ETH had reached Tornado Cash by its update. The episode has sharpened focus on oracle design because cryptographic authentication only shows an authorized key signed a report, while timestamp freshness, price plausibility and settlement safety require separate controls.