Particle.news

Ostium Suffers $18M Oracle Attack on Arbitrum

Authorized automation that submitted future-dated price reports faked profitable trades and exposed gaps in oracle signer controls and settlement checks.

Overview

  • Security firm Blockaid reported that an attacker used a registered PriceUpKeep forwarder to submit future-dated, authorized oracle reports that made losing positions appear profitable and triggered large vault payouts.
  • The drain removed roughly $18 million in USDC from Ostium’s public liquidity vault, with other security firms later tracing flows and estimating total outflows between about $18 million and $22 million.
  • Ostium paused all trading, froze open positions and paused withdrawals while urging users to revoke contract approvals as the team works with external security firms on an ongoing investigation.
  • At the time of the incident Ostium held about $63 million in total value locked, so the exploit removed close to one-third of the protocol’s liquidity and directly affects liquidity providers and traders whose funds are temporarily unavailable.
  • The breach, reported on July 15, highlights a rising pattern of attacks that exploit oracle and keeper infrastructure rather than smart-contract code and is intensifying calls for stronger signer key management, timestamp checks, multi-source price validation, and reconsideration of instant settlement designs.