Prices From the Future Fool the Oracle, Ostium Drained of $24 Million in Five Minutes

marsbitPublished on 2026-07-17Last updated on 2026-07-17

Abstract

Ostium, a perpetual trading platform, suffered a security incident on July 15, resulting in significant losses from its public liquidity vault. Initial analyses from Blockaid, Cyvers, and PeckShield estimate losses of up to $24 million. The exploit occurred over a five-minute window. According to security firms, the core issue was not a missing signature, but a data integrity failure: a registered price oracle (PriceUpKeep) submitted authorized price reports with manipulated future timestamps, creating false trading profits. The protocol’s verification process confirmed the signatures as authorized but did not enforce price sanity checks or timestamp boundaries, allowing the manipulated data to be accepted for settlement. This caused the liquidity vault to pay out on these fraudulent profits. Ostium’s co-founder confirmed the team paused trading within an hour and is collaborating with law enforcement and security experts. The extracted funds were reportedly swapped for ETH, with a portion moved to Tornado Cash. The incident highlights risks in DeFi oracle designs where cryptographic signature verification is insufficient without additional safeguards for data validity, timestamp freshness, and price reasonableness. Ostium's response and planned fixes—including stricter timestamp validation, independent price checks, and circuit breakers—will be critical to preventing similar exploits.

Author: CryptoSlate

Compiled by: Deep Tide TechFlow

Deep Tide Insights: This is not missing signatures, but rather authorized signers submitting price data "from the future." When verification passes but the data itself is toxic, where is the DeFi protocol's moat? Ostium has yet to publish final loss accounting and a post-mortem report, leaving huge questions about signer privilege abuse.

On-chain perpetual trading platform Ostium reported that a five-minute security incident caused losses to its public liquidity vaults. Security firms estimate the size of the exploit at up to $24 million.

Co-founder Kaledora Kiernan-Linn confirmed the issue occurred between 14:18 and 14:23 UTC on July 15, affecting the public Ostium Liquidity Provider (OLP) vaults. She stated the team identified the problem within minutes and coordinated a trading halt within an hour. The statement did not provide an exact total loss, root cause, or final post-mortem report.

Security firms say the heart of the issue is *authorized* data, not missing signatures. Blockaid and Cyvers reported that a registered PriceUpKeep forwarder submitted authorized oracle reports with future dates, creating phantom trading profits.

SlowMist said authorized signers provided manipulated data with valid signatures, used for repeated profitable trades. These descriptions remain third-party findings, pending confirmation in Ostium's post-mortem.

Cryptographic attestation can confirm a report was signed by a permitted key. But price reasonableness, timestamp freshness, and settlement security require separate controls.

The OstiumVerifier code linked from Ostium's security documentation recovers the ECDSA signer and checks if the signer is authorized, but this verification function does not enforce price reasonableness tests or timestamp boundaries.

The code does not appear to indicate which implementation version was active during the incident, or if separate contracts applied these checks. Any timestamp, replay, price deviation, or multi-source safeguards must have been run elsewhere in the execution path.

Even if the share price is static, tokenized stocks as collateral can fail

Ostium's protocol documentation states that OLP vaults hold trader collateral and pay winning trades instantly on-chain. If false profits were accepted for settlement, the vault's liquidity footed the bill for those payments.

Public estimates climbed as tracking continued. Blockaid placed the payout near $18 million, Cyvers estimated $23.7 million, and PeckShield later described around $24 million being drained.

SlowMist's lower figure of $11.86 million appears to track a single 11,862,444.782 USDC vault outflow visible in the transaction it cited.

SummerFi DeFi's new exploit shows AI automation now overrides smart contract risk

PeckShield said the withdrawn USDC was swapped for 12,080 ETH, with 10,540 ETH having entered Tornado Cash as of its update. Kiernan-Linn said Ostium is working with law enforcement, SEAL 911, and third-party security experts.

This mechanism distinguishes Ostium from a similar issue at Hedera lending protocol Bonzo Lend four days earlier. Bonzo's incident report stated its verifier accepted a proof without a valid signature. In Ostium's case, security firms claim the reports passed the authorized signer path: authentication succeeded, but the data was allegedly unsafe.

How a zero-signature oracle unlocked $9 million from Hedera DeFi lending protocol Bonzo Lend

Ostium still needs to confirm whether the signer key was compromised, an authorized operator acted maliciously, or another privileged path was abused.

Its fixes will be judged by whether signer isolation, strict timestamp boundaries, independent price checks, rate limiting, and circuit breakers can prevent one trusted path from turning a few minutes of bad data into yet another vault payout.

Related Questions

QWhat is the core security issue that led to the exploitation of the Ostium protocol, according to the article?

AThe core issue was not missing signatures, but the submission of authorized oracle reports containing 'future' price data by a registered PriceUpKeep forwarder. The verification process checked for authorized signers but failed to validate the reasonableness of the price data and timestamp freshness, allowing fraudulent profit claims to be settled.

QWhat was the estimated financial loss to Ostium's public liquidity vault during the five-minute incident?

ASecurity estimates varied, but the figure widely reported was approximately $24 million. Blockaid initially estimated close to $18 million, Cyvers estimated $23.7 million, and PeckShield later described about $24 million being drained.

QHow does the Ostium exploit differ from the recent security incident on Bonzo Lend, as mentioned in the article?

AThe Bonzo Lend incident involved its verifier accepting a proof without a valid signature. In contrast, the Ostium exploit involved oracle reports that *did* have valid signatures from an authorized signer, meaning the authentication succeeded, but the data within the report itself was manipulated and fraudulent.

QWhat are some of the proposed fixes or improvements mentioned to prevent similar incidents in the future?

AThe article suggests that Ostium's response will be judged on its implementation of measures like signer isolation, strict timestamp boundaries, independent price checks, rate limiting, and circuit breakers to prevent a trusted path from being abused to drain the vault.

QWhat happened to a significant portion of the stolen funds after the exploit?

AAccording to PeckShield, the extracted USDC was swapped for 12,080 ETH, and at the time of their update, 10,540 ETH of that had been sent to the privacy mixer Tornado Cash.

Related Reads

Why Bitcoin Holds Above $64,000 After Fed's Hard Pause

**Bitcoin Stabilizes Near $64,000 Following Hawkish Fed Pause** The cryptocurrency market, led by Bitcoin, remained stable around $64,000 despite a volatile reaction to the latest U.S. Federal Reserve meeting. The Fed paused interest rates but signaled a hawkish stance, with three committee members voting for an increase—the highest dissent since 2016. This limits risk appetite but hasn't triggered panic selling. Key market highlights include Bitcoin ETFs seeing a net inflow of $32.1 million, breaking a streak of outflows, while Ethereum ETFs experienced outflows of $18.65 million. Liquidations affected about 90,000 traders. Technically, Bitcoin finds support around $63,000-$63,500, with major resistance near $66,000. While its price is about 49% below its all-time high, institutional demand via ETFs and the absence of mass capitulation support a potential recovery scenario in the second half of the year. Major altcoins showed mixed movements, with Solana attracting capital while Ethereum faced selling pressure despite strong on-chain metrics like a growing staking queue. Regulatory news took a pause as the U.S. Senate delayed the CLARITY Act vote until at least autumn. For the final trading day of July, U.S. inflation and consumer spending data will be crucial. Bitcoin's key levels to watch are $63,000 support and $66,000 resistance. Sustained ETF inflows and Bitcoin holding above $63,000 are seen as positive signs for a potential market recovery later in the year.

cryptonews.ru2h ago

Why Bitcoin Holds Above $64,000 After Fed's Hard Pause

cryptonews.ru2h ago

Trading

Spot
活动图片