Ostium is a synthetic asset protocol that enables institutional and retail traders and hedgers to gain exposure to commodities on-chain.
Odaily News: Headline: "Loss of 23.75 Million USDC: Ostium Price Data Attacked". According to Ostium's monitoring, Ostium has released an update on the security incident. Its liquidity provider treasury was attacked on July 15, resulting in a loss of 23,752,746 USDC. Preliminary investigations indicate that the attacker compromised the off-chain infrastructure that supplies price data to the protocol, submitting disguised, fraudulent price reports. By rapidly opening and closing multiple large positions, the attacker extracted artificially generated profits from the treasury. Ostium stated that trader collateral is stored in separate, isolated smart contracts and was unaffected by this incident; all trading positions remain open. The team paused trading and froze all trading contracts within 60 minutes of the first attack transaction. Currently, Ostium is cooperating with Mandiant, zeroShadow, Collisionless, SEAL 911, and law enforcement agencies, and is coordinating with trading platforms, bridge contracts, and stablecoin issuers to advance the investigation. The engineering team is repairing and strengthening the relevant infrastructure to support a safe resumption of trading. Ostium stated it will notify at least 24 hours in advance before thawing the trading contracts. Once trading resumes, existing positions will be marked at the price at the time of reopening, unaffected by price fluctuations during the suspension.
Ostium, a decentralized perpetual exchange, suffered an oracle attack on Wednesday, resulting in losses of approximately 18 million USDC. The attacker submitted false price reports for future dates using compromised oracle signing keys, generating fictitious trading profits and receiving payouts from the Ostium liquidity vault. Ostium stated that it has identified the issue with the OLP vault, has suspended all trading, and the team is currently investigating. Deployed on Arbitrum, Ostium offers perpetual futures trading for real-world assets including stocks, commodities, forex markets, and indices. At the time of the attack, the total value locked (TVL) in the Ostium protocol was approximately $63 million. The attack drained nearly one-third of this liquidity. In the first five months of 2026, DeFi protocols have lost over $840 million to exploits, including $292 million from KelpDAO and $285 million from Drift Protocol.
perpetual contract DEX Ostium has confirmed an anomaly in its OLP vault. The platform has paused all trading, and the team is currently investigating the issue.
The Securities and Exchange Commission (SEC) of the Philippines has issued an investor alert warning the public against investing on seven cryptocurrency trading platforms: dYdX, Aevo, gTrade, Pacifica, Orderly, Deriv, and Ostium. The SEC stated that these platforms are not registered with the Commission and have not obtained the necessary authorizations required under the Crypto Asset Service Provider (CASP) framework. The SEC also warned that individuals promoting these platforms within the Philippines may face criminal liability, including fines of up to PHP 5,000,000 (approximately USD 89,000) or imprisonment for up to 21 years.
Odaily reports, according to HyperliquidNews monitoring, a whale recently transferred $7.29 million from Ostium to Hyperliquid and then opened 10,124 long positions on the S&P 500, worth approximately $74.33 million. This position currently accounts for 13.03% of the market's open interest.
Odaily reports, perpetual contract DEX Ostium stated that platform trading remains paused following a security incident. User positions remain open but cannot be modified for now, and trading margin funds are still held in the frozen trading smart contract without any movement.Ostium stated that its team is continuously coordinating with relevant authorities, SEAL 911, and multiple security researchers. Updates regarding the resumption of smart contract activities and the timeline for fund recovery will be released subsequently.According to PeckShield monitoring, approximately 24 million USDC from Ostium's public OLP vault was stolen. The attacker subsequently swapped these funds for approximately 12,100 ETH, of which about 10,500 ETH was transferred to Tornado Cash.
According to monitoring by on-chain analyst PeckShield (@PeckShieldAlert), the public OLP vault of decentralized perpetual contract protocol Ostium (@Ostium) was attacked, with approximately 24 million USDC stolen. The attacker subsequently swapped the stolen funds for 12,080 ETH and has transferred 10,540 ETH into the mixer Tornado Cash to obscure the fund flow. On-chain tracing shows that the attacker's initial funds originated from ChangeNow and Bybit, with 1 ETH transferred from each to the attacker's wallet (0x321D...8bfD9).
according to on-chain analyst Yujin's monitoring, half an hour ago, an address (0x321...bfd9) with the DeBank username musti_akrep profited 23.75 million USDC by exploiting a vulnerability on Perp DEX Ostium and withdrew it. The 23.75 million USDC was withdrawn to the Arbitrum chain and immediately exchanged for 12,085 ETH at a price of $1,965. Currently, these 12,085 ETH remain on the Arbitrum chain.
Odaily — Ostium has released an update on the July 15 exploit and a recovery plan for OLP holders. Ostium stated that the attack resulted in approximately $23.75 million being withdrawn from the Ostium Liquidity Pool (OLP), and available evidence suggests the attack may have been carried out by a nation-state actor. As of now, 649,967 USDC has been recovered, and the remaining vault assets currently held by affected users are worth approximately 30% of their pre-incident OLP positions.Ostium launched its recovery portal today and took a snapshot of OLP balances at the time of the incident, identifying a total of 3,666 affected wallets. Of these, 3,321 wallets — or 90.59% — are eligible for full compensation of verified losses through the Phase 1 plan. Users with losses of 1,000 USDC or less can directly claim an equivalent amount in USDC; users with losses exceeding 1,000 USDC may choose to claim 1,000 USDC and forfeit the remaining recovery allocation, or participate in the Phase 2 proportional recovery plan.Phase 2 funding will primarily come from subsequent recovery of attacker funds and a share of Ostium protocol revenue, with the specific revenue share ratio and related arrangements to be announced by October 30.As previously reported, Ostium's off-chain infrastructure was hacked on July 15, resulting in approximately 23.75 million USDC being withdrawn from the OLP vault.
According to court documents, a federal court in New York will hold a hearing today in the case brought by ESS Frontier and Hong Kong lender Minghui Zheng against Ostium, involving a $15 million loan dispute. The two parties are asking the judge to freeze Ostium's assets and refer the dispute to arbitration; Ostium previously lost $23.75 million in an exploit in July.
According to Ostium's official report, the core of this attack lies in the compromise of the off-chain price reporting system permissions, unrelated to smart contract vulnerabilities. After obtaining off-chain authorization, the attacker utilized the protocol's registered legitimate forwarding paths to submit forged prices ($5,000 and $60,000) to the BTC-USD market, atomically completing an open-close position arbitrage cycle within the same transaction. Starting with 100 USDC and rolling to amplify the scale across 8 transactions, they extracted 23.75 million USDC from the OLP vault within 5 minutes until the vault circuit breaker mechanism was triggered. The root cause lies in the off-chain infrastructure lacking a multi-party approval mechanism equivalent to on-chain multi-signature, creating a single-point permission vulnerability. The stolen funds have been converted to ETH and mixed via Tornado Cash; tracking efforts are still ongoing.
Odaily News: Headline: "Loss of 23.75 Million USDC: Ostium Price Data Attacked". According to Ostium's monitoring, Ostium has released an update on the security incident. Its liquidity provider treasury was attacked on July 15, resulting in a loss of 23,752,746 USDC. Preliminary investigations indicate that the attacker compromised the off-chain infrastructure that supplies price data to the protocol, submitting disguised, fraudulent price reports. By rapidly opening and closing multiple large positions, the attacker extracted artificially generated profits from the treasury. Ostium stated that trader collateral is stored in separate, isolated smart contracts and was unaffected by this incident; all trading positions remain open. The team paused trading and froze all trading contracts within 60 minutes of the first attack transaction. Currently, Ostium is cooperating with Mandiant, zeroShadow, Collisionless, SEAL 911, and law enforcement agencies, and is coordinating with trading platforms, bridge contracts, and stablecoin issuers to advance the investigation. The engineering team is repairing and strengthening the relevant infrastructure to support a safe resumption of trading. Ostium stated it will notify at least 24 hours in advance before thawing the trading contracts. Once trading resumes, existing positions will be marked at the price at the time of reopening, unaffected by price fluctuations during the suspension.
Odaily reports, perpetual contract DEX Ostium stated that platform trading remains paused following a security incident. User positions remain open but cannot be modified for now, and trading margin funds are still held in the frozen trading smart contract without any movement.Ostium stated that its team is continuously coordinating with relevant authorities, SEAL 911, and multiple security researchers. Updates regarding the resumption of smart contract activities and the timeline for fund recovery will be released subsequently.According to PeckShield monitoring, approximately 24 million USDC from Ostium's public OLP vault was stolen. The attacker subsequently swapped these funds for approximately 12,100 ETH, of which about 10,500 ETH was transferred to Tornado Cash.
According to monitoring by on-chain analyst PeckShield (@PeckShieldAlert), the public OLP vault of decentralized perpetual contract protocol Ostium (@Ostium) was attacked, with approximately 24 million USDC stolen. The attacker subsequently swapped the stolen funds for 12,080 ETH and has transferred 10,540 ETH into the mixer Tornado Cash to obscure the fund flow. On-chain tracing shows that the attacker's initial funds originated from ChangeNow and Bybit, with 1 ETH transferred from each to the attacker's wallet (0x321D...8bfD9).
Odaily — Ostium has released an update on the July 15 exploit and a recovery plan for OLP holders. Ostium stated that the attack resulted in approximately $23.75 million being withdrawn from the Ostium Liquidity Pool (OLP), and available evidence suggests the attack may have been carried out by a nation-state actor. As of now, 649,967 USDC has been recovered, and the remaining vault assets currently held by affected users are worth approximately 30% of their pre-incident OLP positions.Ostium launched its recovery portal today and took a snapshot of OLP balances at the time of the incident, identifying a total of 3,666 affected wallets. Of these, 3,321 wallets — or 90.59% — are eligible for full compensation of verified losses through the Phase 1 plan. Users with losses of 1,000 USDC or less can directly claim an equivalent amount in USDC; users with losses exceeding 1,000 USDC may choose to claim 1,000 USDC and forfeit the remaining recovery allocation, or participate in the Phase 2 proportional recovery plan.Phase 2 funding will primarily come from subsequent recovery of attacker funds and a share of Ostium protocol revenue, with the specific revenue share ratio and related arrangements to be announced by October 30.As previously reported, Ostium's off-chain infrastructure was hacked on July 15, resulting in approximately 23.75 million USDC being withdrawn from the OLP vault.
Odaily News: Headline: "Loss of 23.75 Million USDC: Ostium Price Data Attacked". According to Ostium's monitoring, Ostium has released an update on the security incident. Its liquidity provider treasury was attacked on July 15, resulting in a loss of 23,752,746 USDC. Preliminary investigations indicate that the attacker compromised the off-chain infrastructure that supplies price data to the protocol, submitting disguised, fraudulent price reports. By rapidly opening and closing multiple large positions, the attacker extracted artificially generated profits from the treasury. Ostium stated that trader collateral is stored in separate, isolated smart contracts and was unaffected by this incident; all trading positions remain open. The team paused trading and froze all trading contracts within 60 minutes of the first attack transaction. Currently, Ostium is cooperating with Mandiant, zeroShadow, Collisionless, SEAL 911, and law enforcement agencies, and is coordinating with trading platforms, bridge contracts, and stablecoin issuers to advance the investigation. The engineering team is repairing and strengthening the relevant infrastructure to support a safe resumption of trading. Ostium stated it will notify at least 24 hours in advance before thawing the trading contracts. Once trading resumes, existing positions will be marked at the price at the time of reopening, unaffected by price fluctuations during the suspension.
Odaily reports, perpetual contract DEX Ostium stated that platform trading remains paused following a security incident. User positions remain open but cannot be modified for now, and trading margin funds are still held in the frozen trading smart contract without any movement.Ostium stated that its team is continuously coordinating with relevant authorities, SEAL 911, and multiple security researchers. Updates regarding the resumption of smart contract activities and the timeline for fund recovery will be released subsequently.According to PeckShield monitoring, approximately 24 million USDC from Ostium's public OLP vault was stolen. The attacker subsequently swapped these funds for approximately 12,100 ETH, of which about 10,500 ETH was transferred to Tornado Cash.
Ostium, a decentralized perpetual exchange, suffered an oracle attack on Wednesday, resulting in losses of approximately 18 million USDC. The attacker submitted false price reports for future dates using compromised oracle signing keys, generating fictitious trading profits and receiving payouts from the Ostium liquidity vault. Ostium stated that it has identified the issue with the OLP vault, has suspended all trading, and the team is currently investigating. Deployed on Arbitrum, Ostium offers perpetual futures trading for real-world assets including stocks, commodities, forex markets, and indices. At the time of the attack, the total value locked (TVL) in the Ostium protocol was approximately $63 million. The attack drained nearly one-third of this liquidity. In the first five months of 2026, DeFi protocols have lost over $840 million to exploits, including $292 million from KelpDAO and $285 million from Drift Protocol.
According to CoinDesk, decentralized exchange Ostium has announced it is the first on-chain trading platform to offer perpetual contracts on individual U.S. equities powered by Nasdaq data, enabling users to gain exposure to U.S. stocks via blockchain infrastructure. Built on Arbitrum, Ostium focuses on perpetual futures pegged to real-world assets, supporting trading in equities, stock indices, foreign exchange, and commodities. Official data shows that since its launch in 2024, the platform has recorded over $50 billion in cumulative trading volume and attracted more than 26,000 traders. This partnership reflects the growing adoption of equity perpetual contracts in on-chain markets and highlights Nasdaq’s accelerated efforts to build tokenized stock trading infrastructure.
on-chain perpetual contract trading platform Ostium has announced a partnership with Nasdaq to utilize its U.S. stock market data to support equity perpetual contract products on the platform.Ostium states that this makes it the first on-chain trading venue backed by Nasdaq data to offer equity perpetual contracts. The platform states that users will be able to gain exposure to U.S. stocks through on-chain infrastructure while retaining features such as transparency, instant settlement, and self-custody.Ostium specializes in on-chain leveraged trading of traditional financial assets, covering categories such as stocks, indices, commodities, ETFs, and forex. To date, the platform has facilitated cumulative trading volumes exceeding $50 billion and has over 26,000 trading users.
Odaily — Ostium has released an update on the July 15 exploit and a recovery plan for OLP holders. Ostium stated that the attack resulted in approximately $23.75 million being withdrawn from the Ostium Liquidity Pool (OLP), and available evidence suggests the attack may have been carried out by a nation-state actor. As of now, 649,967 USDC has been recovered, and the remaining vault assets currently held by affected users are worth approximately 30% of their pre-incident OLP positions.Ostium launched its recovery portal today and took a snapshot of OLP balances at the time of the incident, identifying a total of 3,666 affected wallets. Of these, 3,321 wallets — or 90.59% — are eligible for full compensation of verified losses through the Phase 1 plan. Users with losses of 1,000 USDC or less can directly claim an equivalent amount in USDC; users with losses exceeding 1,000 USDC may choose to claim 1,000 USDC and forfeit the remaining recovery allocation, or participate in the Phase 2 proportional recovery plan.Phase 2 funding will primarily come from subsequent recovery of attacker funds and a share of Ostium protocol revenue, with the specific revenue share ratio and related arrangements to be announced by October 30.As previously reported, Ostium's off-chain infrastructure was hacked on July 15, resulting in approximately 23.75 million USDC being withdrawn from the OLP vault.
According to court filings, the federal court in New York will hear a $15 million loan dispute against on-chain perpetual futures exchange Ostium today. ESS Frontier and Hong Kong-based lender Zheng Minghui sued Ostium earlier this month, seeking a court order to freeze its assets and submit the dispute to arbitration.
According to court documents, a federal court in New York will hold a hearing today in the case brought by ESS Frontier and Hong Kong lender Minghui Zheng against Ostium, involving a $15 million loan dispute. The two parties are asking the judge to freeze Ostium's assets and refer the dispute to arbitration; Ostium previously lost $23.75 million in an exploit in July.
Odaily reports, according to HyperliquidNews monitoring, a whale recently transferred $7.29 million from Ostium to Hyperliquid and then opened 10,124 long positions on the S&P 500, worth approximately $74.33 million. This position currently accounts for 13.03% of the market's open interest.
According to Ostium's official report, the core of this attack lies in the compromise of the off-chain price reporting system permissions, unrelated to smart contract vulnerabilities. After obtaining off-chain authorization, the attacker utilized the protocol's registered legitimate forwarding paths to submit forged prices ($5,000 and $60,000) to the BTC-USD market, atomically completing an open-close position arbitrage cycle within the same transaction. Starting with 100 USDC and rolling to amplify the scale across 8 transactions, they extracted 23.75 million USDC from the OLP vault within 5 minutes until the vault circuit breaker mechanism was triggered. The root cause lies in the off-chain infrastructure lacking a multi-party approval mechanism equivalent to on-chain multi-signature, creating a single-point permission vulnerability. The stolen funds have been converted to ETH and mixed via Tornado Cash; tracking efforts are still ongoing.
据 Ostium 官方推文,链上交易平台 Ostium 宣布将于美东时间 7 月 23 日上午 10:00 重新开放交易。重启后,所有未平仓头寸及挂单将保持原状,并按重启时的实时市场价格重新标记;若头寸在重启价格下触及清算线,将被自动清算;止盈、止损及限价单亦将在重启时按实时价格执行。 交易恢复将分阶段进行,首先开放平仓、追加保证金、修改/取消订单等保护性操作,随后再开放新开仓功能。流动性提供方面,新 OLP 存款暂停,现有 LP 提款将在下一结算周期处理,后续将公布资本恢复方案细节。