
According to Ostium's post-mortem published on Wednesday, the July exploit originated from compromised off-chain infrastructure rather than a flaw in its smart contracts. The attacker gained unauthorized access to the protocol's off-chain infrastructure and used it to submit fraudulent BTC-USD price reports. The core of the attack was a compromise of the off-chain price feed system permissions, not a smart contract vulnerability. After obtaining off-chain authorization, the attacker exploited a registered legitimate forwarding path in the protocol to submit forged prices of $5,000 and $60,000 to the BTC-USD market, completing an arbitrage cycle of opening and closing positions within the same transaction.
During its investigation, Ostium said the initial breach occurred outside the protocol's on-chain infrastructure. The exploit began with a small test transaction involving a 100 USDC position, producing roughly 897.8 USDC in artificial profit before the attacker expanded the operation. The attacker started with 100 USDC, scaled up through eight transactions, and drained 23.75 million USDC from the OLP treasury within five minutes until the treasury's circuit breaker was triggered. Following the successful test, the attacker executed the primary batch of transactions, transferring about 11.9 million USDC to a beneficiary wallet. Six additional standalone exploit cycles followed, bringing the total loss from the OLP vault to 23.75 million USDC.
While the exploit succeeded in draining funds from the liquidity vault, Ostium said its automated monitoring systems detected the abnormal activity before additional withdrawals could take place. The protocol subsequently halted trading while its investigation continued and has since migrated to a new production environment with updated security controls. Trading resumed on July 23 after the migration was completed. The team added that trader collateral remained unaffected throughout the incident because user margin stayed inside the protocol's trading contracts rather than the compromised liquidity pool.
The root cause of the attack lies in the lack of a multi-party approval mechanism in the off-chain infrastructure equivalent to on-chain multisig, creating a single point of access vulnerability. This security gap allowed the attacker to gain unauthorized access to the protocol's off-chain infrastructure and submit fraudulent price reports. The stolen funds have been converted to ETH and mixed through Tornado Cash, making tracking efforts ongoing. The incident has drawn attention to the security of supporting infrastructure that decentralized finance protocols rely on for external market data.
Ostium is still finalizing a separate recovery plan for liquidity providers whose funds were affected by the exploit, with further details to be released in a dedicated update. The protocol confirmed that its smart contracts and governance multisigs were not compromised during the attack. The exploit occurred only weeks after Ostium expanded its institutional presence through a partnership with Nasdaq announced in May, with the protocol having processed more than $50 billion in cumulative trading volume before the incident.