Ostium Blames Off-Chain Breach for $24 Million Exploit
Ostium, an onchain perpetuals exchange, has revealed that its recent $24 million exploit was caused by an off-chain breach rather than a vulnerability in its smart contracts or protocol multisigs.
The incident occurred on July 15 when the attacker leveraged unauthorized access to Ostium's off-chain infrastructure to submit fraudulent BTC-USD price reports. This enabled them to generate artificial trading profits from the public OLP vault.
The team behind Ostium stated that this initial unauthorized access took place off-chain, and they have no evidence of a vulnerability in their smart-contract code logic or a compromise of the multisigs that govern the protocol.
The attacker used forwarder paths recognized by the protocol to execute the main batch, resulting in 11.9 million USDC transferred to the beneficiary wallet. They later executed six further standalone cycles, draining a total of 23.75 million USDC from the OLP vault.