{"id":35874,"date":"2026-07-30T08:04:33","date_gmt":"2026-07-30T08:04:33","guid":{"rendered":"https:\/\/bitunikey.com\/news\/ostium-blames-off-chain-breach-for-23-75m-usdc-exploit\/"},"modified":"2026-07-30T08:05:09","modified_gmt":"2026-07-30T08:05:09","slug":"ostium-blames-off-chain-breach-for-23-75m-usdc-exploit","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/ostium-blames-off-chain-breach-for-23-75m-usdc-exploit\/","title":{"rendered":"Ostium blames off chain breach for $23.75M USDC exploit"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">Ostium has concluded that its July exploit originated from compromised off-chain infrastructure rather than a flaw in its smart contracts, after an investigation found the attacker manipulated price reporting to drain 23.75 million USDC from the protocol\u2019s liquidity vault.<\/p>\n<div id=\"cn-block-summary-block_d6cd42c8ac9353797e7ee6e09638561e\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Ostium said its investigation found the July exploit originated from compromised off chain infrastructure rather than a flaw in its smart contracts.<\/li>\n<li>Fraudulent BTC USD price reports allowed the attacker to drain 23.75 million USDC from the protocol\u2019s OLP liquidity vault.<\/li>\n<li>The protocol said automated monitoring detected the attack, trading resumed on July 23, and user collateral remained unaffected.<\/li>\n<li>A recovery plan for affected liquidity providers is being finalized and will be shared in a separate update.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>According to Ostium\u2019s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/Ostium\/status\/2082540358219747422\" target=\"_blank\" rel=\"nofollow\">post-mortem published on Wednesday<\/a>, the attacker gained unauthorized access to the protocol\u2019s off-chain infrastructure and used it to submit fraudulent BTC-USD price reports.\u00a0<\/p>\n<p>The manipulated reports allowed the attacker to create artificial trading profits at the expense of the public OLP vault, while the protocol found no evidence that its smart contracts or governance multisigs had been compromised.<\/p>\n<h2 class=\"wp-block-heading\">Ostium says exploit bypassed off-chain systems<\/h2>\n<p>During its investigation, Ostium said the initial breach occurred outside the protocol\u2019s on-chain infrastructure. The team stated that its findings did not identify any vulnerability in the protocol\u2019s smart contract logic or any compromise involving the multisigs responsible for governing the protocol.<\/p>\n<p>Instead, the attacker abused forwarder paths that the protocol already recognized as valid. Ostium explained that the exploit began with a small test transaction involving a 100 USDC position, producing roughly 897.8 USDC in artificial profit before the attacker expanded the operation.<\/p>\n<p>Following the successful test, the attacker executed the primary batch of transactions, transferring about 11.9 million USDC to a beneficiary wallet. Ostium said six additional standalone exploit cycles followed, bringing the total loss from the OLP vault to 23.75 million USDC.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<p>Earlier reporting from blockchain security firm Blockaid had attributed the incident to a compromised oracle signer private key, saying the attacker bypassed the protocol\u2019s price verification process by submitting manipulated price reports through a registered PriceUpKeep forwarder. At the time, Blockaid estimated that between $11.86 million and $18 million USDC had been withdrawn during approximately 20 trading loops, based on the exploit activity visible on-chain while the attack was still unfolding.<\/p>\n<h2 class=\"wp-block-heading\">Automated monitoring limited additional losses<\/h2>\n<p>While the exploit succeeded in draining funds from the liquidity vault, Ostium said its automated monitoring systems detected the abnormal activity before additional withdrawals could take place. The protocol subsequently halted trading while its investigation continued and has since migrated to a new production environment with updated security controls.<\/p>\n<p>Trading resumed on July 23 after the migration was completed.<\/p>\n<p>Ostium also said trader collateral remained unaffected throughout the incident because user margin stayed inside the protocol\u2019s trading contracts rather than the compromised liquidity pool.<\/p>\n<p>The team added that it is still finalizing a separate recovery plan for liquidity providers whose funds were affected by the exploit. According to the protocol, further details will be released in a dedicated update.<\/p>\n<h2 class=\"wp-block-heading\">Oracle infrastructure remained central to the attack<\/h2>\n<p>Although Ostium\u2019s latest report attributes the incident to unauthorized access to its off-chain infrastructure, its findings are consistent with the attack path previously outlined by Blockaid, which concluded that compromised signing credentials allowed fraudulent price reports to pass the protocol\u2019s verification process.<\/p>\n<p>According to Blockaid\u2019s earlier analysis, the attacker repeatedly opened and closed positions through delegated actions after submitting favorable future-dated price reports. Because the manipulated reports appeared valid to the protocol, each trading cycle generated profits for the attacker while transferring losses to the OLP liquidity vault instead of relying on a vulnerability in the smart contract code itself.<\/p>\n<p>The incident has drawn attention to the security of supporting infrastructure that decentralized finance protocols rely on for external market data. In Ostium\u2019s case, both the protocol\u2019s post-mortem and Blockaid\u2019s earlier investigation concluded that the exploit did not originate from flaws in the core smart contracts.<\/p>\n<h2 class=\"wp-block-heading\">Ostium exploit followed Nasdaq partnership<\/h2>\n<p>The exploit occurred only weeks after Ostium expanded its institutional presence through a partnership with Nasdaq announced in May. At the time, the protocol said Nasdaq\u2019s market data would support equity perpetual products listed on the platform.<\/p>\n<p>Ostium also disclosed during that announcement that it had processed more than $50 billion in cumulative trading volume.<\/p>\n<p>Before the exploit, the protocol had raised approximately $27.8 million from investors including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute and GSR, according to previous company disclosures.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Ostium has concluded that its July exploit originated from compromised off-chain infrastructure rather than a flaw in its smart contracts, after an investigation found the attacker manipulated price reporting to&hellip;<\/p>\n","protected":false},"author":1,"featured_media":34806,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-35874","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35874","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=35874"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35874\/revisions"}],"predecessor-version":[{"id":35875,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35874\/revisions\/35875"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/34806"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=35874"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=35874"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=35874"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}