
A post-mortem said a compromised oracle signer key let an attacker submit fabricated BTC price reports, while trader collateral stayed untouched and a recovery plan for liquidity providers is still pending.
Ostium said its July 15 exploit, which drained 23,752,746 USDC from its OLP vault, was caused by a compromise of its off-chain price-signing infrastructure rather than a flaw in smart contracts or protocol multisigs. In a post-mortem, the Arbitrum-based perpetuals exchange said the attack ran between 14:18 and 14:24 UTC on July 15, after an attacker used a valid signer key and a legitimately registered forwarder to push fabricated Bitcoin price reports, open a position at $5,000 and close it near $60,000 in the same transaction, generating artificial profits paid from the public OLP vault. Ostium said the exploit began with a 100 USDC test and escalated to larger batches, including one that moved roughly $11.86 million, before the vault’s circuit breaker triggered twice and stopped further withdrawals. The protocol said trader collateral was not affected because user margin remained in trading contracts and the false reports were not used to settle other traders’ positions. Ostium resumed trading on July 23 after migrating to a new production environment with multi-party approvals and added security controls, while a separate recovery plan for liquidity providers is still being finalized. The incident also highlighted a broader DeFi security gap, with the compromised component sitting in off-chain infrastructure that standard smart-contract audits and many bug bounties do not examine.