$24 Million Exploit Hits Ostium Due to Off-Chain Infrastructure Compromise
Ostium, an onchain perpetuals exchange, recently suffered a $24 million exploit due to unauthorized access to its off-chain infrastructure. According to the exchange's post-mortem report, the attacker compromised Ostium's off-chain infrastructure and submitted fraudulent BTC-USD price reports, allowing them to generate artificial trading profits from the public OLP vault.
The attack occurred on July 15, with the attacker using forwarder paths already recognized by the protocol. They first tested with a $100 USDC position to generate approximately $897.8 of artificial profit before executing the main batch, resulting in $11.9 million USDC transferred to the beneficiary wallet.
Ostium's automated monitoring system detected the activity and prevented further withdrawals. The exchange has since migrated to a new production environment with updated security controls and trading resumed on July 23. Trader collateral was not affected, but a separate recovery plan for liquidity providers is being finalized.