Ostium, a decentralized perpetuals exchange on Arbitrum, lost roughly $18 million on Wednesday after attackers compromised an oracle signer key and manipulated the platform’s price feed to generate fake trading profits, according to blockchain security firm Blockaid.

Blockaid points to oracle report abuse
In a post on X, Blockaid said the attacker used a registered PriceUpKeep forwarder and future-dated authorized oracle reports to create artificial trading profits. That process triggered a multi-million payout from Ostium’s liquidity vault, with funds leaving in the form of Circle-issued stablecoin USDC.
Ostium said on X: "We are aware of the issue with the OLP vault. We have paused all trading. The team is investigating."
Loss came from a protocol holding about $63 million
Ostium is built on Arbitrum and offers perpetual futures tied to real-world assets, including stocks, commodities, foreign exchange markets, and indices. It operates as a decentralized exchange, meaning users largely retain control of their funds and do not provide personally identifiable information.
At the time of the attack, the protocol held about $63 million in total value locked. On that basis, the exploit drained close to one-third of its liquidity.
Another large DeFi loss in 2026
The incident adds to what the report described as one of the worst years on record for DeFi exploits. DeFi refers to financial applications that run natively on blockchain networks without third-party intermediaries such as banks.
More than $840 million was stolen from DeFi protocols in the first five months of 2026, including $292 million from KelpDAO and $285 million from Drift Protocol. Hackers also targeted Resolv Labs in June, stealing more than $25 million.
Security warnings on AI-driven vulnerability discovery
Security experts have warned that advances in artificial intelligence are accelerating exploit discovery. Danny Jenkins, CEO and co-founder of ThreatLocker, previously told Decrypt, "AI is far better at reviewing code than most people and finding potential vulnerabilities in it."
Jenkins said current AI systems are already speeding up vulnerability discovery, while newer models such as Mythos could significantly expand those capabilities. He called it an imminent "big problem."
He added: "It will be only a matter of time until someone bad gets access to it."
Claude Opus 4.8 cited in Zcash vulnerability case
In May, security researcher Taylor Hornby used Anthropic's Claude Opus 4.8 to identify a four-year-old counterfeiting vulnerability in Zcash. The example was cited as a sign that frontier AI models are becoming increasingly effective at finding complex software flaws.

