Ostium Halts Trading After Oracle Exploit, With OLP Vault Loss Estimated at Up to $18 Million

Ostium Halts Trading After Oracle Exploit, With OLP Vault Loss Estimated at Up to $18 Million

N
News Editor
2026-07-15 16:12:18
Ostium, an Arbitrum-based perpetuals protocol focused on real-world assets, halted all trading on Wednesday after an attack tied to its oracle and keeper infrastructure drained USDC from its OLP liquidity vault. Blockchain security firm Blockaid said the attacker used a registered PriceUpKeep forwarder together with future-dated authorized oracle reports to manufacture trading profit and trigger a payout of about $18 million. The cited exploit transaction, 0x359f8c05...d4870e0, and the attacker address were both identified on Arbitrum. Other onchain observers have put the loss lower, with some estimates near $11.86 million, while Ostium has not yet released its own accounting. Data from DefiLlama showed Ostium held roughly $63.3 million in total value locked shortly before the incident. The protocol confirmed the issue, paused all markets, and said its team was investigating. The case also raises questions about trust assumptions around keeper and oracle systems, especially because Ostium’s bug bounty scope had treated registered keepers and their forwarders as trusted components.
OstiumArbitrumoracle exploitUSDCDeFi securityperpetualsBlockaid

Ostium halted all trading on Wednesday after an attacker allegedly manipulated its oracle system and drained as much as $18 million in USDC from the protocol’s OLP liquidity vault.

The Arbitrum-based protocol offers perpetual trading tied to real-world assets. It previously raised about $27.8 million from backers including General Catalyst and Jump Crypto.

Blockaid details the exploit, while loss estimates vary

Onchain security firm Blockaid said the attacker “used a registered PriceUpKeep forwarder and future-dated authorized oracle reports to create artificial trade profit, triggering a ~$18M USDC payout from the vault.”

Blockaid published both the exploit transaction and the attacker address on Arbitrum. The transaction cited in its disclosure, 0x359f8c05...d4870e0, is confirmed onchain.

There is still no single loss figure accepted by all parties. Blockaid put the payout at roughly $18 million. Independent onchain observers estimated a smaller number, with some placing the drained amount near $11.86 million. Ostium has not published its own accounting of the loss.

According to DefiLlama data, the protocol had about $63.3 million in total value locked shortly before the attack. Even the lower-end estimate would represent a meaningful share of the vault’s balance.

Ostium confirms the incident and pauses markets

Ostium acknowledged the issue and suspended trading. In a post on X, the protocol wrote: “We are aware of the issue with the OLP vault. We have paused all trading. The team is investigating.”

Ostium allows users to trade perpetual contracts on assets such as gold, oil, equity indices, and foreign exchange directly from a crypto wallet, with settlement in USDC on Arbitrum, a Layer 2 network. According to the protocol, the OLP vault has supported more than $33 billion in cumulative trading volume across more than 50 markets.

The attack appears to have hit a trusted part of the system

The component Blockaid says was used in the exploit sat inside a part of the system that Ostium had previously told security researchers to treat as safe. In the protocol’s bug bounty scope, all registered keepers, including PriceUpKeep, “and their forwarders are assumed to be trusted and operating correctly,” while findings that require a compromised or malicious keeper fall outside the program.

The mechanism of the attack and the top-end loss number remain Blockaid’s stated findings and have not been independently reconciled. Blockaid’s post referred to a “registered forwarder” and “future-dated authorized oracle reports.” It did not say a private key had been compromised, even though some descriptions of the incident have framed it that way.

Ostium has not said how the attacker gained the ability to submit those reports, and it has not released a final loss tally.

Another case involving keeper and oracle infrastructure

The incident adds to a string of exploits involving automated keeper and oracle systems that DeFi protocols use to bring real-world prices onchain.

Summer.fi lost about $6.04 million in a share-price manipulation on July 6, according to its post-mortem. In April 2025, an attacker drained roughly $7.5 million from KiloEx across three chains by impersonating a trusted keeper and feeding false prices to the protocol, a structure that Blockaid said resembles what happened at Ostium.

The pattern highlights a repeated weakness for protocols that settle trades against offchain data. The delivery machinery for those prices is often trusted by default. Once that layer is controlled, a protocol can end up paying out on trades that never actually made money.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.