-
Hackers stole $23.75 million from Ostium’s liquidity provider vault by compromising off-chain price reporting systems, not the platform’s smart contracts.
-
Trader collateral remained safe in a separate contract, but Ostium decided to halt trading while they investigated the incident.
-
The attacker moved fast, converted the stolen funds to Ethereum first, and thereafter, sent over 10,500 ETH through Tornado Cash.
The Arbitrum-based decentralized exchange Ostium recently fell victim to a hack attack. The hackers exploited Ostium’s off-chain price systems and drained $23.75 million from the platform’s liquidity vault.
As a result, the trading platform had to stop all trade activities as it tried to investigate the situation after calling it a security breach. This hack is part of the emerging trend in decentralized finance involving targeting external systems rather than smart contract platforms.
How the Attack Worked
The attacker compromised Ostium’s off-chain infrastructure responsible for supplying market prices to the protocol. According to the platform’s investigation, the hacker submitted fraudulent price reports that appeared legitimate to the system.
Using these manipulated prices, the attacker rapidly opened and closed large leveraged positions. These trades appeared highly profitable, and the protocol paid out those artificial profits from the liquidity provider vault. The hacker exploited a registered component called the PriceUpKeep forwarder to inject fake price data into the system.
Security researchers noted that the attacker used future-dated authorized price reports that passed validation checks. The blockchain contracts operated exactly as designed. They simply acted on compromised pricing information that looked legitimate.
Early blockchain analysis suggested the exploit initially drained around $18 million. However, Ostium’s ongoing investigation increased the confirmed losses to $23.75 million. The platform identified eight payouts to a single wallet, including transfers worth approximately $11.86 million, $4.49 million, and $3.59 million.
Trading On Hold, But User Funds are Safe
Ostium emphasized that trader collateral remained safe throughout the incident. Customer funds reside in a separate smart contract from the affected liquidity provider vault.
The company confirmed that the hackers didn’t steal trader collateral and that existing long and short positions remain secure. Positions were not automatically liquidated during the attack.
The platform suspended trading and froze affected contracts within one hour of the first exploit transaction. Although user funds remain intact, traders currently cannot manage their open positions because all trading activity has been halted.
Ostium promised to provide at least 24 hours’ notice before resuming trading operations. When trading restarts, positions will be marked to the reopening market price rather than prices during the suspension period.
Stolen Funds Move Through Ethereum
PeckShield, a blockchain security company, was able to monitor the movement of the stolen funds almost immediately after the heist took place. The hacker converted the stolen USDC tokens to 12,080 Ethereum and transferred 10,540 ETH using Tornado Cash, a crypto mixer.
The crypto mixer obscures all transaction information; therefore, making it incredibly hard to trace and recover the funds. Although blockchain transactions are still transparent, the use of mixers makes it extremely difficult for the authorities.
Ostium has reportedly notified relevant authorities and continues monitoring the movement of stolen funds. The platform is collaborating with security firms including Mandiant, zeroShadow, Collisionless, and SEAL 911 on the investigation.
Off-Chain Infrastructure Under Fire
The incident highlights a critical security challenge for decentralized finance. Many DeFi platforms rely on oracles and other off-chain services to deliver real-world prices onto blockchains. These external systems are essential because blockchains cannot independently access live financial market data.
If attackers get access to those external systems, they can mess with trading results without touching the blockchain at all. More and more security researchers are pointing out that hackers go after trusted data feeds these days instead of messing with the smart contracts everyone’s watching so closely.
Strong contract audits offer limited protection when privileged off-chain systems or signing infrastructure are compromised. The attack serves as another reminder that blockchain security extends beyond on-chain code. It includes every system responsible for generating, signing, and delivering trusted data. The vulnerability of external systems is also evident in claims of hackers selling access to security platforms like Malwarebytes.
The incident comes at a challenging time for Ostium, which had grown rapidly as a decentralized perpetual trading platform. Before everything went sideways, the company had already handled more than $50 billion in trades and pulled in about $27.8 million from investors.
Regular traders didn’t lose money directly, but the attack highlights a bigger issue for the whole DeFi world. Securing smart contracts alone is no longer enough. As protocols increasingly depend on external infrastructure, those off-chain systems are becoming attractive targets for attackers.