Ostium says July 15 exploit drained 23.75 million USDC via off-chain compromise

Ostium says July 15 exploit drained 23.75 million USDC via off-chain compromise

A post-mortem said a compromised oracle signer key let an attacker submit fabricated BTC price reports, while trader collateral stayed untouched and a recovery plan for liquidity providers is still pending.

BTC
USDC
ARB

Fact Check
Multiple independent sources corroborate every element of the claim. The Block's post-mortem article and its X post confirm 23.75M USDC drained via off-chain infrastructure compromise, fraudulent BTC-USD price reports, unaffected trader collateral, and a still-finalizing LP recovery plan. CoinNess and Coincu independently report the same 23.75M USDC figure and off-chain (non-smart-contract) nature. The earlier Block article documents the July 15 timing and the price-report/oracle manipulation mechanism. All specifics in the claim match the reported facts.
Summary

Ostium said its July 15 exploit, which drained 23,752,746 USDC from its OLP vault, was caused by a compromise of its off-chain price-signing infrastructure rather than a flaw in smart contracts or protocol multisigs. In a post-mortem, the Arbitrum-based perpetuals exchange said the attack ran between 14:18 and 14:24 UTC on July 15, after an attacker used a valid signer key and a legitimately registered forwarder to push fabricated Bitcoin price reports, open a position at $5,000 and close it near $60,000 in the same transaction, generating artificial profits paid from the public OLP vault. Ostium said the exploit began with a 100 USDC test and escalated to larger batches, including one that moved roughly $11.86 million, before the vault’s circuit breaker triggered twice and stopped further withdrawals. The protocol said trader collateral was not affected because user margin remained in trading contracts and the false reports were not used to settle other traders’ positions. Ostium resumed trading on July 23 after migrating to a new production environment with multi-party approvals and added security controls, while a separate recovery plan for liquidity providers is still being finalized. The incident also highlighted a broader DeFi security gap, with the compromised component sitting in off-chain infrastructure that standard smart-contract audits and many bug bounties do not examine.

Terms & Concepts
  • oracle signer key: A cryptographic key used to sign price data that a protocol trusts for trade settlement.
  • off-chain price-signing infrastructure: External systems that generate and sign market data before it is submitted on-chain.
  • circuit breaker: An automated safeguard designed to halt activity when abnormal conditions or losses are detected.