Ostium Protocol Loses Over 20 Million Dollars in Latest Oracle Exploit Attack

Ostium, a decentralized finance protocol specializing in perpetual futures trading, has been exploited for over $20 million in an oracle manipulation attack. The incident forced the platform to halt all trading activity as security teams investigated the breach.

The attacker exploited weaknesses in Ostium oracle infrastructure, using a registered price-feed forwarder and future-dated oracle reports to book fraudulent trading profits. By manipulating the price data that the protocol relied on for settlement, the attacker was able to withdraw funds from the OLP vault.

Security firm Blockaid detected the exploit as it was unfolding, flagging the suspicious transactions. The attack is the latest in a string of oracle manipulation incidents that have plagued DeFi protocols, highlighting the critical importance of securing price feed infrastructure.

Following the exploit, the attacker moved approximately 10,540 ETH to Tornado Cash, a cryptocurrency mixing service often used to launder stolen funds. The use of a mixer indicates limited intent to return the funds voluntarily, according to security researchers.

Oracle exploits have become one of the most common attack vectors in DeFi, as protocols rely on external data feeds to determine prices, liquidations, and other critical functions. When these feeds are compromised, attackers can execute trades at manipulated prices to extract value.

Ostium has not announced a timeline for resuming trading. The protocol will need to rebuild its oracle infrastructure and potentially seek reimbursement from insurance protocols or through legal channels.

The incident adds to a growing list of DeFi exploits in 2026, which has already seen over $1.3 billion in losses across 344 security incidents according to CertiK mid-year report.

This article was adapted from Protos. Read the original here.