- In the latest post on X, Ostium revealed that it is preparing to resume trading after the exploit, with a 24-hour advance notice.
- On July 15, Ostium suffered a cyber attack on the OLP liquidity vault following a compromised off-chain oracle signer key.
- Ostium Labs will contribute from its balance sheet for affected LPs alongside partners.
On July 20, Ostium, a leading decentralized perpetuals trading platform on Arbitrum in real-world assets (RWAs), announced that it is preparing to relaunch this week after facing a security incident that led to the loss of approximately $23.75 million USDC from its liquidity provider vault, known as the OLP.
The post shared on X said, “We are working toward a relaunch this week. We will provide a notification 24 hours before trading resumes. Final checks are being done by our auditors, third-party cybersecurity experts, and engineering team.”
Ostium Prepares to Resume Trading with 24-Hour Advance Notice
In the official post shared on X, Ostium shared important details for the resumption of trading. Positions will be marked to the live market price at the moment trading resumes. Importantly, traders will not face liquidation due to price movements that occurred during the pause. However, any position falling below its liquidation threshold based on the live market price at relaunch will be subject to liquidation. Pending orders will carry over unchanged.
The team mentioned that final checks are being carried out by auditors, third-party cybersecurity experts, and the engineering team. For affected liquidity providers, Ostium Labs is developing a recovery plan and intends to contribute from its own balance sheet, along with support from new and existing partners.
Ostium has urged users to rely only on official channels for updates and warned against scams involving direct messages or requests for private keys.
“For affected liquidity providers, our team is working hard on a recovery plan. Ostium Labs intends to contribute from its own balance sheet alongside new and existing partners. We know this is the update you are waiting for, and will share it as soon as we can,” stated in the post.
Ostium Faces Major Exploits Following Attack On Off-Chain Oracle Infrastructure
The cyberattack took place on July 15. According to the official statement of Ostium, the attacker compromised off-chain oracle infrastructure after gaining control of an oracle signer private key. This allowed the submission of manipulated, future-dated price reports through the protocol’s PriceUpKeep forwarder.
Using these falsified prices, the attacker executed around 20 looped trades to generate artificial profits without real market risk. This triggered unauthorized payouts totaling roughly $23.75 million USDC, with reports initially citing between $18 million and $24 million, from the public OLP vault on Arbitrum. The stolen USDC was swapped for approximately 12,085 ETH, with a portion of around 10,540 ETH later moved to the Tornado Cash mixer to obscure the trail.
Ostium has taken important measures to avoid further exploitation of the protocol. It has paused trading and smart contracts within 60 minutes of the first malicious transaction. The exploit targeted shared liquidity in the public vault, not individual user collateral.
“Impacted liquidity providers and the safe resumption of trading remain our top priority, and we are working around the clock towards the path forward. As a reminder, we will give at least 24 hours’ notice before trading contracts are unfrozen. Upon re-open, trader positions will be marked to the price at re-open, independent of interim price movements,” stated in the post.
After facing the attack, Ostium mentioned top-tier partners for investigation and remediation, including Mandiant for cybersecurity, zeroShadow, Collisionless, SEAL 911, and law enforcement agencies. The team is also coordinating with exchanges, bridges, and stablecoin issuers to track and freeze assets linked to the cyber attack.
This cyber attack is showing constant vulnerabilities present in decentralized finance around oracle infrastructure and private keys. It comes amid a recent series of cyber attacks that took place in the last 6 months. This year, many major protocols, like Kelp DAO and Drift Protocol, suffered major cyber attacks, resulting in millions of dollars of loss.
The upcoming relaunch and LP recovery plan will be important for restoring lost confidence of users in the platform. However, the full details on compensation timelines are still pending. While the RWA sector is growing rapidly amid growing regulatory clarity, incidents like the Ostium hack are raising questions about the link between the traditional financial world and tokenized assets.