Decentralized finance protocol Ostium has suffered an exploit that drained approximately $18 million from its vault on the Arbitrum network. The attacker manipulated the platform’s oracle price feeds to generate fraudulent trading profits.
The exploit, which occurred on Wednesday, targeted Ostium’s OLP vault by compromising an oracle signer key. This allowed the attacker to submit manipulated price data to the protocol. Using future-dated oracle reports and a registered price feed forwarder, the hacker was able to book fake trading profits that were then withdrawn as legitimate funds.
Ostium is a perpetuals exchange that lets users trade synthetic assets with leverage. The platform relies on oracles to provide accurate price data for its trading pairs. In this case, the attacker exploited the gap between the oracle’s reported prices and actual market prices, a classic oracle manipulation attack vector.
Blockchain security firm Blockaid identified the exploit as it was unfolding and alerted the platform. Ostium responded by halting trading on the protocol to prevent further losses. The total damage has since been revised upward, with security firm PeckShield now estimating the losses at approximately $24 million after tracking additional fund movements.
The attacker has begun moving stolen funds through Tornado Cash, a cryptocurrency mixing service, in an effort to obscure the trail. Blockchain analysts are monitoring the addresses involved.
The Ostium incident is the latest in a string of oracle manipulation attacks that have plagued DeFi protocols in 2026. Earlier this month, lending protocol Bonzo Lend lost $9 million on Hedera in a similar Supra oracle exploit, and Summer.fi suffered a $6 million flash loan attack. Security researchers have warned that oracle infrastructure remains one of the weakest points in DeFi, as a single compromised price feed can lead to outsized losses.
This article was adapted from Decrypt. Read the original here.
