News Report Technology
July 30, 2026

Ostium Loses $23.7M After Off-Chain Price Oracle Breach, Recovers Trading Post-Migration

In Brief

Ostium lost $23.75M USDC in an off-chain oracle breach. No smart contract flaw; trading resumed July 23 after migration as fund recovery continues.

Ostium Loses $23.7M After Off-Chain Price Oracle Breach, Recovers Trading Post-Migration

Ostium, an Arbitrum-based RWA trading platform, suffered a major security breach on July 15 that resulted in the withdrawal of approximately 23.75 million USDC from its public liquidity provider vault. 

The attack compromised the protocol’s off-chain price infrastructure rather than its on-chain smart contracts or governance systems, highlighting how decentralized finance platforms remain vulnerable to weaknesses in traditional IT infrastructure.

According to the company’s incident report published on social media platform X, attackers exploited Ostium’s pull-based price settlement system, which relies on off-chain data sources to generate signed price reports for markets including BTC-USD. 

Having gained unauthorized access to this infrastructure, the attackers submitted falsified reports showing Bitcoin at $5,000 and $60,000—values far removed from actual market rates. Between 14:18 and 14:23 UTC, they executed eight rapid open-and-close trades through legitimate forwarder paths already recognized by the protocol. 

By opening positions at one manipulated price and closing them at the other within atomic transactions, the attacker generated artificial profit-and-loss calculations that forced the OLP vault to pay out nearly 24 million USDC in illegitimate profits.

Ostium stressed that the incident did not stem from smart contract logic flaws or compromised governance multi-signatures. Trader collateral remained secure in trading contracts throughout the incident, and no other user positions were settled against the manipulated prices.

Swift On-Chain Containment and Migration to Hardened Infrastructure

Automated monitoring systems detected the anomalous activity within minutes, triggering vault circuit breakers that prevented additional withdrawals. The team executed its first on-chain containment transaction at 14:55 UTC and froze all trading contracts within 20 minutes after the initial test transaction.

In the aftermath, Ostium migrated to a new production environment featuring enhanced multi-party approval controls and resumed trading on July 23. The stolen USDC was converted to ETH and dispersed across a network of attacker-controlled wallets, with a substantial portion routed through Tornado Cash, complicating recovery efforts. 

Ostium has retained cybersecurity firms Mandiant and SEAL 911, alongside blockchain intelligence specialists zeroShadow and Collisionless, to conduct forensic investigations and trace the funds. 

The company is actively coordinating with law enforcement, exchanges, and bridges to freeze assets where possible, and expects to publish a recovery plan for affected liquidity providers in the coming days.

Disclaimer

In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.

About The Author

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

More articles
Alisa Davidson
Alisa Davidson

Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.

Shufti, Jumio, Sumsub, And Beyond: Top 6 Identity Verification And Compliance Platforms To Know In 2026

Shufti, Sumsub, Incode, Veriff, Persona and Jumio compared on compliance lifecycle coverage, pricing transparency and fraud detection ...

Know More

2026 AI Market Claims Vs SEC Fillings: Linkmate Analysis

Is the AI market really all just PR talk or there's a deeper math going on in ...

Know More
Read More
Read more
Gate Update: Platform Ranks Top 3 In RWA Perpetual Trading As Stock Futures Log Third Consecutive Month Of Triple-Digit Growth
Digest News Report Technology
Gate Update: Platform Ranks Top 3 In RWA Perpetual Trading As Stock Futures Log Third Consecutive Month Of Triple-Digit Growth
September 11, 2026
OpenAI Brings Research, Modeling, And Pitchbook Automation To Wall Street With New ChatGPT For Financial Services
Opinion Business Technology
OpenAI Brings Research, Modeling, And Pitchbook Automation To Wall Street With New ChatGPT For Financial Services
September 11, 2026
Brand Trust Beats Fees For 46% Of Crypto Users, And Paybis CEO Innokenty Isers Says Platforms Must Lead With Licensing Transparency To Earn It
Interview Business Technology
Brand Trust Beats Fees For 46% Of Crypto Users, And Paybis CEO Innokenty Isers Says Platforms Must Lead With Licensing Transparency To Earn It
September 11, 2026
Anthropic’s New Threat Intelligence Report Reveals AI’s Growing Role In Cybercrime, Influence Campaigns And State-Sponsored Operations
News Report Technology
Anthropic’s New Threat Intelligence Report Reveals AI’s Growing Role In Cybercrime, Influence Campaigns And State-Sponsored Operations
September 11, 2026