On July 15, a hacker siphoned off 23.75 million USDC from Ostium’s OLP vault by exploiting fraudulent BTC-USD price feeds. The perpetuals exchange confirmed the breach occurred outside its smart contracts, pinpointing an off-chain infrastructure vulnerability as the root cause.

The attacker manipulated the protocol by submitting false Bitcoin price reports via trusted forwarder channels already recognized by the system. This artificial data made it appear as though trades were generating massive profits, allowing the hacker to drain liquidity from the public OLP vault, which supports active trading on the platform. A small test position of 100 USDC was quickly inflated to nearly 900 USDC in fake gains before the large-scale withdrawals followed. The initial main transfer moved 11.9 million USDC to an external wallet, followed by six more trading cycles that drained the rest.

Security Measures and Recovery Efforts

Ostium's smart contracts and multisignature wallets came through unscathed. The investigation revealed no faults in the on-chain codebase, and trader collateral remained untouched inside the protocol’s trading contracts. Losses affected only the OLP vault funds. Automated monitoring halted the exploit early enough to prevent further damage.

After migrating to a new production environment with reinforced security controls, Ostium restarted trading services on July 23. The company is now crafting a recovery plan for liquidity providers impacted by the theft and promises to disclose more updates soon.

This material is for informational purposes and should not be considered financial advice.