- Ostium concluded the $23.75 million exploit originated from compromised off-chain infrastructure, not smart contract vulnerabilities or protocol multisigs, investigators found.
- Fraudulent BTC-USD price reports generated artificial profits, draining 23.75 million USDC from the OLP vault before monitoring blocked further withdrawals.
- Trader collateral remained secure while Ostium migrated production systems, strengthened security controls, and prepared a recovery plan for liquidity providers.
Ostium has concluded that the $23.75 million USDC exploit targeting its OLP vault stemmed from a compromise of its off-chain infrastructure. According to the protocol’s post-mortem, investigators found no evidence that smart contract vulnerabilities or governance multisigs contributed to the attack. Instead, the attacker manipulated BTC-USD price reports after gaining unauthorized access to supporting infrastructure.
According to Ostium, the attacker submitted fraudulent BTC-USD price reports through forwarder paths that the protocol already recognized. Those manipulated reports created artificial trading profits within the public OLP vault. As a result, the attacker extracted millions of dollars without exploiting flaws in the protocol’s deployed smart contracts.
The exploit started with a small test transaction involving a 100 USDC position, generating approximately 897.8 USDC in artificial profit and confirming that the attack method worked.
Also Read: $592 Million Asset Manager Discloses Franklin XRP ETF Investment.
Fraudulent price reports enabled repeated withdrawals
The main exploit transferred about 11.9 million USDC to a beneficiary wallet, after which the attacker completed six more standalone exploit cycles, bringing the total drained from the OLP vault to 23.75 million USDC.
According to Ostium, automated monitoring systems detected the suspicious transactions during the attack. Consequently, the protocol blocked further withdrawals and limited additional losses. The team emphasized that the initial breach occurred entirely within its off-chain infrastructure rather than its on-chain environment.
Moreover, Ostium stated that trader collateral remained secure throughout the incident. User margin stayed inside the protocol’s trading contracts and was never exposed during the exploit. The team has since migrated its production systems to a new environment with stronger security controls. Trading resumed on July 23 following the completion of those upgrades.
Recovery plan follows security upgrades.
Besides restoring operations, Ostium is preparing a separate recovery plan for affected liquidity providers. The protocol said it will publish further details in a dedicated update once the plan is finalized. Meanwhile, the protocol reaffirmed that strengthening its production environment remains a priority following the breach.
The exploit came only months after Ostium partnered with Nasdaq to support equity perpetual products using the exchange operator’s market data. At the time of that announcement, the protocol reported processing more than $50 billion in cumulative trading volume, highlighting the scale of its operations before the incident.
Conclusion
Ostium’s investigation determined that compromised off-chain infrastructure, rather than weaknesses in its smart contracts, enabled the $23.75 million exploit. The protocol has resumed trading, enhanced its production environment, and is preparing a recovery framework for affected liquidity providers.
Also Read: Bitcoin (BTC) holds below $64K as major altcoins trade mixed while COTI (COTI) leads daily gainers
