2 min read

Ostium loses $23.75 million in price-feed attack

Ostium says an attacker stole $23.75 million after manipulating off-chain price feeds, while trader collateral and open positions remained protected.

Image: BleepingComputer

The Ostium trading platform says an attacker stole $23.75 million from its liquidity provider vault last week by compromising off-chain infrastructure that supplies prices to the protocol.

According to an update published yesterday, the attacker submitted illegitimate price reports that appeared valid. They then rapidly opened and closed large positions, generating artificial profits from the manipulated prices.

Trader collateral was stored in a separate contract and was not affected, Ostium said. Existing positions also remain open.

Recommended reading

Estée Lauder discloses Oracle data breach

How the Ostium exploit worked

Ostium is a decentralized trading platform built on Arbitrum, a finance-focused blockchain scaling solution. It lets users speculate on traditional and crypto-asset prices directly from a cryptocurrency wallet. External data feeds provide prices, while trades are settled in USDC, a cryptocurrency designed to maintain a 1:1 peg with the US dollar.

The company first notified its community on July 16, saying trading had been paused because of a security incident. Ostium said relevant authorities had been notified and that it was tracking the movement of stolen funds, but it did not initially disclose technical details.

In its latest update, the company described the incident as an attack on the off-chain infrastructure that feeds prices into Ostium. The attacker manipulated those prices to profit from the liquidity provider vault.

Blockchain security firm PeckShieldAlert said the exploiter swapped the stolen USDC for 12,080 Ethereum, then deposited 10,540 Ethereum into TornadoCash, a cryptocurrency mixer.

Trading remains paused

Ostium said the funds used for leveraged positions are stored in a separate smart contract and were not affected. Ordinary traders' collateral was not stolen, and existing long and short positions were neither closed nor liquidated.

Those positions remain recorded but are effectively frozen. Ostium paused all trading within 60 minutes of the first exploit transaction. The company is now securing the affected infrastructure and evaluating how to proceed for liquidity providers.

Notice on the Ostium trading page
Notice on the Ostium trading page

Trading was still paused five days after the incident. Ostium promised to give users at least 24 hours' notice before operations resume; positions will then be marked to the reopening price.

The company also said it will publish a post-mortem analysis with technical details in the coming days.

Article image
Article image
Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via BleepingComputer

/ Keep reading