Prices From the Future Fool the Oracle, Ostium Drained of $24 Million in Five Minutes

marsbitОпубліковано о 2026-07-17Востаннє оновлено о 2026-07-17

Анотація

Ostium, a perpetual trading platform, suffered a security incident on July 15, resulting in significant losses from its public liquidity vault. Initial analyses from Blockaid, Cyvers, and PeckShield estimate losses of up to $24 million. The exploit occurred over a five-minute window. According to security firms, the core issue was not a missing signature, but a data integrity failure: a registered price oracle (PriceUpKeep) submitted authorized price reports with manipulated future timestamps, creating false trading profits. The protocol’s verification process confirmed the signatures as authorized but did not enforce price sanity checks or timestamp boundaries, allowing the manipulated data to be accepted for settlement. This caused the liquidity vault to pay out on these fraudulent profits. Ostium’s co-founder confirmed the team paused trading within an hour and is collaborating with law enforcement and security experts. The extracted funds were reportedly swapped for ETH, with a portion moved to Tornado Cash. The incident highlights risks in DeFi oracle designs where cryptographic signature verification is insufficient without additional safeguards for data validity, timestamp freshness, and price reasonableness. Ostium's response and planned fixes—including stricter timestamp validation, independent price checks, and circuit breakers—will be critical to preventing similar exploits.

Author: CryptoSlate

Compiled by: Deep Tide TechFlow

Deep Tide Insights: This is not missing signatures, but rather authorized signers submitting price data "from the future." When verification passes but the data itself is toxic, where is the DeFi protocol's moat? Ostium has yet to publish final loss accounting and a post-mortem report, leaving huge questions about signer privilege abuse.

On-chain perpetual trading platform Ostium reported that a five-minute security incident caused losses to its public liquidity vaults. Security firms estimate the size of the exploit at up to $24 million.

Co-founder Kaledora Kiernan-Linn confirmed the issue occurred between 14:18 and 14:23 UTC on July 15, affecting the public Ostium Liquidity Provider (OLP) vaults. She stated the team identified the problem within minutes and coordinated a trading halt within an hour. The statement did not provide an exact total loss, root cause, or final post-mortem report.

Security firms say the heart of the issue is *authorized* data, not missing signatures. Blockaid and Cyvers reported that a registered PriceUpKeep forwarder submitted authorized oracle reports with future dates, creating phantom trading profits.

SlowMist said authorized signers provided manipulated data with valid signatures, used for repeated profitable trades. These descriptions remain third-party findings, pending confirmation in Ostium's post-mortem.

Cryptographic attestation can confirm a report was signed by a permitted key. But price reasonableness, timestamp freshness, and settlement security require separate controls.

The OstiumVerifier code linked from Ostium's security documentation recovers the ECDSA signer and checks if the signer is authorized, but this verification function does not enforce price reasonableness tests or timestamp boundaries.

The code does not appear to indicate which implementation version was active during the incident, or if separate contracts applied these checks. Any timestamp, replay, price deviation, or multi-source safeguards must have been run elsewhere in the execution path.

Even if the share price is static, tokenized stocks as collateral can fail

Ostium's protocol documentation states that OLP vaults hold trader collateral and pay winning trades instantly on-chain. If false profits were accepted for settlement, the vault's liquidity footed the bill for those payments.

Public estimates climbed as tracking continued. Blockaid placed the payout near $18 million, Cyvers estimated $23.7 million, and PeckShield later described around $24 million being drained.

SlowMist's lower figure of $11.86 million appears to track a single 11,862,444.782 USDC vault outflow visible in the transaction it cited.

SummerFi DeFi's new exploit shows AI automation now overrides smart contract risk

PeckShield said the withdrawn USDC was swapped for 12,080 ETH, with 10,540 ETH having entered Tornado Cash as of its update. Kiernan-Linn said Ostium is working with law enforcement, SEAL 911, and third-party security experts.

This mechanism distinguishes Ostium from a similar issue at Hedera lending protocol Bonzo Lend four days earlier. Bonzo's incident report stated its verifier accepted a proof without a valid signature. In Ostium's case, security firms claim the reports passed the authorized signer path: authentication succeeded, but the data was allegedly unsafe.

How a zero-signature oracle unlocked $9 million from Hedera DeFi lending protocol Bonzo Lend

Ostium still needs to confirm whether the signer key was compromised, an authorized operator acted maliciously, or another privileged path was abused.

Its fixes will be judged by whether signer isolation, strict timestamp boundaries, independent price checks, rate limiting, and circuit breakers can prevent one trusted path from turning a few minutes of bad data into yet another vault payout.

Пов'язані питання

QWhat is the core security issue that led to the exploitation of the Ostium protocol, according to the article?

AThe core issue was not missing signatures, but the submission of authorized oracle reports containing 'future' price data by a registered PriceUpKeep forwarder. The verification process checked for authorized signers but failed to validate the reasonableness of the price data and timestamp freshness, allowing fraudulent profit claims to be settled.

QWhat was the estimated financial loss to Ostium's public liquidity vault during the five-minute incident?

ASecurity estimates varied, but the figure widely reported was approximately $24 million. Blockaid initially estimated close to $18 million, Cyvers estimated $23.7 million, and PeckShield later described about $24 million being drained.

QHow does the Ostium exploit differ from the recent security incident on Bonzo Lend, as mentioned in the article?

AThe Bonzo Lend incident involved its verifier accepting a proof without a valid signature. In contrast, the Ostium exploit involved oracle reports that *did* have valid signatures from an authorized signer, meaning the authentication succeeded, but the data within the report itself was manipulated and fraudulent.

QWhat are some of the proposed fixes or improvements mentioned to prevent similar incidents in the future?

AThe article suggests that Ostium's response will be judged on its implementation of measures like signer isolation, strict timestamp boundaries, independent price checks, rate limiting, and circuit breakers to prevent a trusted path from being abused to drain the vault.

QWhat happened to a significant portion of the stolen funds after the exploit?

AAccording to PeckShield, the extracted USDC was swapped for 12,080 ETH, and at the time of their update, 10,540 ETH of that had been sent to the privacy mixer Tornado Cash.

Пов'язані матеріали

The Verdict in Choi Tae-won's Divorce Case: Revealing the Inheritance Undercurrent Behind SK Hynix's Trillion-Won Empire

SK Group Chairman Chey Tae-won's high-profile divorce case, involving a record 1.38 trillion won settlement, has drawn attention to the succession plans for Korea's second-largest conglomerate, especially its crown jewel, SK hynix. Unlike traditional chaebol scripts centered on the eldest son, Chey's three children from his marriage to former President Roh Tae-woo's daughter, Roh Soh-yeong, are carving distinct, non-traditional paths. Eldest daughter Chey Yun-jung (b. 1989) is seen as the most evident successor. With a scientific and consulting background, she holds executive roles at SK bioscience and SK Inc.'s growth support department, focusing on future strategy and biopharma. Her marriage is to an AI infrastructure entrepreneur, not a traditional business alliance. Second daughter Chey Min-jung (b. 1991) took a unique route, voluntarily serving as a South Korean naval officer, including an anti-piracy deployment. She later worked on policy and strategy for SK hynix in Washington D.C. before co-founding an AI-driven healthcare startup. She married a former U.S. Marine Corps officer, connecting her to U.S. defense and policy circles—networks crucial for a global semiconductor giant. The only son, Chey In-geun (b. 1995), who studied physics like his father, worked briefly at SK E&S before joining McKinsey. Despite fitting the traditional "heir" profile as the eldest son, he remains silent and holds no public position or shares in SK, suggesting the old succession playbook is obsolete. As SK hynix's valuation soars, becoming a geopolitical asset in the AI era, the heirs' legitimacy is no longer automatic. They must prove themselves in fields like AI biotech, global policy, and strategic consulting. Their marriages also reflect new elite networks in tech and defense, not old political alliances. Their inheritance is the complex challenge of navigating a globalized, tech-driven world, not just a corporate throne.

marsbit6 год тому

The Verdict in Choi Tae-won's Divorce Case: Revealing the Inheritance Undercurrent Behind SK Hynix's Trillion-Won Empire

marsbit6 год тому

From OpenSea to OpenRouter: Is Alex Atallah Repeating His 'Exit at the Peak' Playbook?

From OpenSea to OpenRouter: Is Alex Atallah Repeating His "Exit at the Peak" Playbook? According to the Wall Street Journal, payments giant Stripe is in talks to acquire the AI model aggregation platform OpenRouter in a potential deal valuing the company near $100 billion. This would mark founder Alex Atallah's second creation of a company reaching a $100 billion valuation, following his co-founding of NFT marketplace OpenSea. OpenRouter, founded just over three years ago, has grown rapidly by acting as a unified gateway for developers to access over 400 AI models. It currently has about 10 million users and processes over 200 trillion tokens monthly. While the platform's annualized revenue is around $50 million, its valuation has skyrocketed from $1.3 billion in March 2026. The potential acquisition by Stripe, a company OpenRouter's founder once likened it to, represents a major expansion into AI infrastructure for the payments leader. This move echoes Atallah's previous timing with OpenSea, where he departed before the NFT market's significant downturn. For OpenRouter, selling now may be strategic. Despite its scale, its business model—charging a 5-5.5% fee on AI inference calls—faces pressure from competition, open-source models, and potential price wars among model providers, limiting its profitability narrative for an IPO. A key asset for potential acquirers like Stripe is OpenRouter's vast repository of real-world AI usage data, which offers unique insights into model performance and developer preferences that are difficult to replicate. Whether this potential deal signifies a new valuation benchmark for AI infrastructure or another market peak signal remains to be seen.

链捕手7 год тому

From OpenSea to OpenRouter: Is Alex Atallah Repeating His 'Exit at the Peak' Playbook?

链捕手7 год тому

Торгівля

Спот
活动图片