Ostium Breach: Attackers Exploit Off-Chain Systems for 23.75M USDC
Ostium, a perpetuals exchange, has released its findings on a security breach that occurred on July 15. The attack drained 23.75 million USDC from the protocol's OLP vault.
The company ruled out any flaws in its smart contracts or multisig wallets, stating that an off-chain security breach was to blame. The attacker gained unauthorized access to off-chain systems and submitted false BTC-USD price reports to the protocol, allowing them to record artificial trading profits.
Ostium's investigation found that the attacker used forwarder paths already recognized by the protocol to generate false profits. A test position worth 100 USDC generated about 897.8 USDC in profit before the larger transactions began.
The main batch transferred 11.9 million USDC to a beneficiary wallet, with six more standalone trading cycles completed using the same method. Ostium's automated monitoring systems detected the activity and stopped further withdrawals before more funds could leave the vault.