Ostium lost $237,000 due to an off-chain price oracle vulnerability; trading has returned to normal after the migration.
In Short
Ostium lost $237,500 USDC due to an off-chain oracle vulnerability. There were no flaws in the smart contract itself; after migration was completed, trading resumed on July 23 and fund recovery efforts are ongoing.
Ostium, an Arbitrum-based RWA trading platform, suffered a major security vulnerability on July 15, resulting in the extraction of approximately $237,500 USDC from its public liquidity provider vault.
This attack compromised the protocol's off-chain price infrastructure rather than its on-chain smart contracts or governance system, highlighting that decentralized finance platforms remain vulnerable to weaknesses in traditional IT infrastructure.
According to the incident report published by the company on social media platform X, attackers exploited Ostium's pull-based price settlement system, which relied on off-chain data sources to generate signed price reports for markets including BTC-USD.
After illegally infiltrating this infrastructure, attackers submitted false reports showing Bitcoin prices at $5,000 and $60,000—prices far removed from the real market price. Between 14:18 and 14:23 UTC, they quickly executed eight open-and-close trades using a protocol-approved legitimate forwarding path.
The attackers opened positions at one manipulated price and closed at another, creating artificial profit and loss calculations in atomic transactions, forcing the OLP vault to pay nearly $240,000 USDC in illicit profits.
Ostium emphasized that the incident was not due to flaws in smart contract logic or compromise of the governance multi-signature mechanism. During the incident, traders' collateral remained safe in trading contracts, and other users' positions were not affected by the price manipulation.
Rapid On-Chain Isolation and Migration to Hardened Infrastructure
Automated monitoring systems detected abnormal activity within minutes, triggering a vault circuit breaker to prevent further withdrawals. At 14:55 UTC, the team executed the first on-chain isolation transaction and froze all trading contracts within 20 minutes of the initial test transaction.
Following the incident, Ostium migrated to a new production environment with enhanced multi-party approval controls and resumed trading on July 23. The stolen USDC was swapped for ETH and dispersed across a network of attacker-controlled wallets, with a large portion routed through Tornado Cash, making recovery efforts much more complicated.
Ostium engaged cybersecurity companies Mandiant and SEAL 911, as well as blockchain intelligence experts zeroShadow and Collisionless, to conduct forensic investigations and trace the movement of funds.
The company is actively coordinating with law enforcement, exchanges, and bridging platforms to freeze assets where possible, and expects to announce a recovery plan for affected liquidity providers in the coming days.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Garmin EMEA Managing Director Sean Biddlecombe sells 986 shares for $288,780.23
Saba Capital Income & Opportunities Fund sets July 31 distribution at $0.085 per share
Saba Capital Income & Opportunities Fund II sets USD 0.058 per share July distribution
Mink Brook Asset Management reports DLH Holdings common share purchase worth $41,530.04
