Skip to main content
Emerging ThreatsData Breaches

Hackers Exploit Off-Chain Infrastructure, Steal $23.7 Million from Ostium

Brightly-lit trading floor with computer screens and financial data displays.

$23.75 million was siphoned from Ostium’s liquidity provider vault after an attacker fed the protocol false prices and used rapid trades to convert that manipulation into cash, the company says.

The mechanics: off-chain price feeds, fake reports, rapid trades

Ostium’s latest update describes the incident as an “attack on off-chain infrastructure that feeds Ostium prices,” in which an attacker “submitted illegitimate price reports disguised as valid ones,” then “rapidly opened and closed large positions to generate artificial profits.” According to the platform, those profits were drawn from the liquidity provider vault; trader collateral held in a separate contract was not taken.

The company first notified its community about the incident on July 16, stating that trading had to be paused “due to a security incident.” Ostium says trading was paused within 60 minutes of the first exploit transaction.

How Ostium’s design limited — and exposed — different assets

Ostium is a decentralized trading platform built on the Arbitrum finance-native blockchain scaling solution. The protocol accepts price inputs from external data feeds and settles trades in USDC, a cryptocurrency designed to maintain a 1:1 peg to the US dollar. Ostium clarified that trading amounts for leveraged positions are stored in a separate smart contract and were not impacted by this incident.

As a result, the company reports, the collateral posted by ordinary traders was not stolen and existing long and short positions were not closed or liquidated. Those positions remain recorded on-chain but are effectively frozen while the platform is paused.

On-chain trail: swaps to Ethereum and deposits to TornadoCash

Blockchain security firm PeckShieldAlert reported findings on the post-exploit token movements. According to PeckShieldAlert, the exploiter swapped the stolen USDC for 12,080 Ethereum, and then deposited 10,540 Ethereum to TornadoCash, a cryptocurrency mixer.

Ostium has said the movement of stolen funds is being tracked and that relevant authorities were notified. The company provided no additional public detail about the attacker’s identity or the exact off-chain systems compromised.

What this means for liquidity providers, ordinary traders, and security teams

  • Liquidity providers: Funds were removed from the liquidity provider vault. Ostium says it is “working to secure the affected infrastructure and determine a path forward for liquidity providers,” leaving the immediate financial outcome for those providers to be decided.
  • Ordinary traders: Collateral and existing positions were not taken; however, positions remain frozen while trading is paused. Ostium has promised to provide at least 24 hours’ notice before operations resume and said positions will be marked to the reopening price at that time.
  • Security teams and technologists: The incident centers on off-chain price feeds, underlining the risk that external data ingestion can pose to on-chain settlement. Ostium has pledged a post-mortem analysis with technical details “in the coming days,” information security teams will likely scrutinize those findings to understand how illegitimate reports were accepted as valid.

Ostium’s commitments and the immediate status

Five days after the incident, trading on Ostium remained paused, the company said. Ostium stated it would provide at least 24 hours’ notice before resuming operations and that it will mark positions to the reopening price when it does so. The platform also promised to publish a post-mortem with technical details and is working to secure the affected infrastructure while determining next steps for liquidity providers.

The company also reported that the relevant authorities were notified and that movement of the stolen funds is being tracked, but supplied no additional operational or investigative details in its public updates.

This breach underscores a specific vulnerability: when price inputs originate off-chain, attackers who can manipulate those inputs can translate falsified values into on-chain financial outcomes. Ostium’s immediate steps — pausing trading within an hour, isolating leveraged-trading amounts in a separate contract, and promising a technical post-mortem — set a basic remediation sequence. What remains to be seen is how Ostium will resolve losses in the liquidity provider vault and what the forthcoming technical report will reveal about the abused off-chain systems.

Original reporting: Bleeping Computer