GoPlus said the attack on Ostium, an RWA trading platform on Arbitrum, may have been caused by a leak of an administrator account’s private key, with estimated losses of about $11.86 million. According to GoPlus, the attacker first opened a position through the openTrade function, then manipulated prices via performUpkeep, and finally used closeTradeMarket to lock in profit. The firm noted that prices submitted through performUpkeep require signature verification from an authorized account, suggesting that the private key tied to that account may have been exposed. Foresight News had earlier reported that Ostium was attacked on the previous evening, after which the platform halted all trading. The team is currently investigating the incident.
GoPlus said the exploit targeting Ostium, an RWA trading platform on Arbitrum, may have resulted from a leaked private key tied to an administrator account. Estimated losses were put at about $11.86 million.
According to GoPlus, the attacker first opened a position through the openTrade function, then manipulated prices through performUpkeep, and finally called closeTradeMarket to profit from the move. GoPlus added that prices submitted through performUpkeep must be verified with a signature from an authorized account. The fact that the attack succeeded indicates that the private key for that authorized account may have been compromised.
Foresight News had earlier reported that Ostium was attacked on the previous evening. The platform has since suspended all trading, and the team is investigating.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.