Ostium Hack: Perp DEX Loses $23.75M in Oracle Key Exploit, Resumes Trading July 23

1 week ago 3

Rommie Analytics

On July 15, 2026, the perpetuals DEX Ostium was drained of $23.75 million USDC after an attacker got hold of an oracle signer private key and used it to manufacture fake profitable trades until the vault ran dry. Ostium paused trading within an hour of the first malicious transaction, and after an eight-day investigation and hardening effort, reopened the platform on July 23.

Unlike the smart contract bugs that once dominated DeFi hack headlines, this attack targeted the off-chain infrastructure that feeds prices into the protocol — the part most audits and bug bounties are never paid to look at.

What exactly happened to Ostium?

The root cause was a compromised oracle signer private key rather than a flaw in Ostium's Solidity code. Security firm Blockaid, which first flagged the incident, reported that the attacker used a registered PriceUpKeep forwarder to submit future-dated, authorized oracle reports. Those reports tricked the protocol into thinking a series of trades were profitable.

From there the attacker ran roughly 20 looped open-and-close trades through delegated actions, pulling repeated payouts from Ostium's main OLP (liquidity provider) vault without ever taking on real market exposure. The...

Read Entire Article