Ostium has concluded that its July exploit originated from compromised off-chain infrastructure rather than a flaw in its smart contracts, after an investigation found the attacker manipulated price reporting to drain 23.75 million USDC from the protocol’s liquidity vault. According to Ostium’s post-mortem, the attacker gained unauthorized access to the protocol’s off-chain infrastructure and used it to submit fraudulent BTC-USD price reports. The manipulated reports allowed the attacker to create artificial trading profits at the expense of the public OLP vault, while the protocol found no evidence that its smart contracts or governance multisigs had been compromised.
Incident Details
Ostium explained that the exploit began with a small test transaction involving a 100 USDC position, producing roughly 897.8 USDC in artificial profit before the attacker expanded the operation. Following the successful test, the attacker executed the primary batch of transactions, transferring about 11.9 million USDC to a beneficiary wallet.
Aftermath
Ostium said its automated monitoring systems detected the abnormal activity before additional withdrawals could take place, and subsequently halted trading while its investigation continued. The protocol has since migrated to a new production environment with updated security controls, and trading resumed on July 23. Ostium also said trader collateral remained unaffected throughout the incident because user margin stayed inside the protocol’s trading contracts rather than the compromised liquidity pool. A separate recovery plan for liquidity providers whose funds were affected by the exploit is still being finalized.



