Within eight days in July, two decentralised perpetuals exchanges on Arbitrum were emptied: Ostium on 15 July, AFX Trade on 22 July. Together the attackers took roughly $42 million.
In both cases the entry point was not a smart contract but a private key held by people. That is where the industry's central marketing promise starts to crack. "Decentralised" has meant: nobody can take your money because nobody holds it. With many providers it actually means the deposit sits behind a bridge whose signing keys are kept on servers users know nothing about.
The two cases in detail
Ostium, 15 July
At the Arbitrum perp DEX Ostium, the private key of a price oracle was compromised. That allowed fake, future-dated price reports to be signed and fed through the protocol's own PriceUpKeep infrastructure. The attacker opened a position at a fabricated bitcoin price of $5,000 and closed it at the actual price of around $60,000. The difference came out of the liquidity providers' vault: $18 million to $23.75 million, depending on the assessment. Trading was suspended.
One detail from the bug bounty programme stands out: the exact component the attack ran through was explicitly excluded from it. Secur...


English (US)