Ostium Halts Trading After Oracle Exploit Drains Millions From Liquidity Vault

Ostium has paused trading on its perpetual exchange following an oracle-related exploit that drained between $18 million and $22 million from its OLP liquidity vault. Blockchain security firms identified the attack as the latest in a series of oracle manipulation incidents targeting DeFi protocols.

The attacker exploited Ostium’s price feed infrastructure by compromising an oracle signer key, allowing them to manipulate pricing data and extract funds from the protocol’s liquidity pools. Security firm PeckShield later reported that the exploiter routed approximately 10,540 ETH through Tornado Cash, a mixing service commonly used to obscure transaction trails.

Ostium advised users to revoke contract approvals as a precautionary measure while the team investigates the incident and works on a recovery plan. The exploit is the 14th major oracle-related incident in 2026, highlighting the persistent vulnerability of DeFi protocols that rely on external price data.

Oracle manipulation attacks work by corrupting the data feed that smart contracts use to determine asset prices. When an attacker can control or influence the price feed, they can execute trades at favorable artificial prices, draining liquidity before the manipulation is detected.

The Ostium incident follows a pattern of similar exploits targeting DeFi platforms, including the recent $9 million Bonzo Lend exploit on Hedera and the Summer Finance $6 million flash loan attack. These incidents have prompted increased scrutiny of oracle security across the DeFi ecosystem.

Security researchers have called for improved oracle design, including multiple independent data sources, time-weighted average pricing mechanisms, and circuit breakers that can pause trading when anomalous price movements are detected. Some protocols are also exploring the use of settlement delays as a defense against rapid oracle manipulation attacks.

For Ostium, the exploit represents a significant setback. The protocol will need to address the underlying vulnerability and develop a plan to restore user funds before it can resume normal operations.

This article was adapted from Cointelegraph. Read the original here.