Finst

Ostium Loses $18 Million After Oracle Hack on Arbitrum

The exploit hit the main liquidity vault of the Arbitrum perpetual DEX, where a compromised oracle key let price data be manipulated. The incident puts RWA DeFi and oracle infrastructure security under pressure.

Ostium Loses $18 Million After Oracle Hack on Arbitrum

Key Takeaways

  • Arbitrum-based perpetual DEX Ostium was hit by an exploit that drained nearly $18 million USDC from the main liquidity vault.
  • The attack used a compromised oracle signer private key and manipulated price data to generate profits through repeated trades.
  • Ostium says the investigation is ongoing and is asking users to follow official channels for withdrawal guidance and security updates.

Arbitrum-based perpetual DEX Ostium was exploited today, with nearly $18 million (€15.8 million) in USDC drained from its main liquidity vault. Early findings point to a compromised oracle signer private key, which allowed the attacker to distort price data and extract profits through repeated trades without ever holding a real market position.

How the Attack Worked

Security firm Blockaid reported the incident on July 15, 2026. According to the report, the attacker relied on a registered PriceUpKeep forwarder and future-dated authorized oracle reports to manufacture fake trading gains. From there, the exploit moved through about 20 open-and-close loops using delegated actions, which steadily drained the vault.

On-chain data indicates that somewhere between $11.86 million (€10.4 million) and $18 million (€15.8 million) USDC was taken, representing roughly 32% to 35% of the protocol’s then-current TVL of about $34 million (€29.8 million). The main transactions are visible on Arbiscan. Ostium describes itself as a perpetuals exchange for real-world assets such as stocks, commodities, forex, and indices, all built on Arbitrum.

Why This Matters More Broadly

The exploit adds pressure to a corner of crypto that has drawn more attention lately: RWA-focused DeFi protocols that depend heavily on complex oracle systems. In April, Drift Protocol, a Solana-based perpetuals exchange, was also hit by a major exploit that paired a compromised key with manipulated oracle pricing. Cases like these make it clear that private key security and timing controls can still be weak spots in hybrid DeFi designs.

Pressure on Oracle Security

Ostium had raised about $27.8 million (€24.4 million) from investors including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute, and GSR. Even so, the incident shows that strong funding and audits do not automatically shield a project from attacks on oracle infrastructure. The protocol says the investigation is still underway and is telling users to rely on official channels for withdrawal guidance and security updates.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.