VERSE PRESS

Crypto News, Global First.

Ostium Loses Up to $18 Million in Oracle Key Exploit, Halts All Trading

An attacker drained roughly 28% of the Arbitrum-based perpetuals protocol's vault on July 15 by weaponizing a compromised price-feed signing key against its own automation infrastructure.

|

Ostium, a decentralized exchange on the Arbitrum network that lets users trade perpetual futures contracts on real-world assets such as gold, forex pairs, and equity indices, has suspended all trading after suffering an exploit that removed between $11.86 million and $18 million in USDC from its liquidity pool, known as the OLP vault. The protocol's total value locked stood at approximately $63 million at the time of the attack. Blockchain security firm Blockaid was the first to identify the incident and flag the attack vector publicly.


How the Attack Worked

Ostium's price data system relies on a third-party automation network called Gelato to write asset prices on-chain at the moment a trade is executed. At the center of this process sit two distinct components: a smart contract called PriceUpKeep, which serves as the authorized trigger for price writes, and a Gelato Dedicated Message Forwarder at address 0x6297ce1A61C2C8a72BfB0DE957F6B1cF0413141e, which is the only address authorized to call that trigger, according to Ostium's own documentation.

According to Blockaid, the attacker obtained the private key for the oracle signer tied to this system and used it to submit price reports bearing future-dated timestamps.

By making positions appear profitable at settlement, the attacker was able to open and close approximately 20 trade loops through the protocol's delegated action system, pulling out vault funds each time. After draining an estimated $11.86 million to $18 million in USDC, the attacker converted the funds to ETH and spread them across multiple wallets.

Blockaid described the mechanism directly: "The attacker used a registered PriceUpKeep forwarder and future-dated authorized oracle reports to generate artificial trading profits." The relevant mainnet forwarder address is 0x6297ce1A61C2C8a72BfB0DE957F6B1cF0413141e, which Ostium's own documentation identifies as the sole authorized trigger for price-feed updates. This quote reached Verse Press via Wu Blockchain's relay of Blockaid's findings; a directly published statement from Blockaid had not been confirmed at time of publication.

Ostium's team posted a brief notice on X: "We are aware of an issue with the OLP vault, have paused all trading, and the team is investigating." As of publication, no full post-mortem or recovery plan has been released, and it remains unclear whether the oracle key was compromised externally or through an insider.


Protocol Background

Ostium was founded by Kaledora Kiernan-Linn and Marco Antonio Ribeiro, both Harvard alumni and former Bridgewater Associates employees.

The protocol raised $27.8 million in total funding, including a Series A co-led by General Catalyst and Jump Crypto in December 2025. The Block reported the Series A at $24 million in fresh funding; CoinDesk's coverage of the same round placed the figure at $20 million. Verse Press was unable to independently reconcile the discrepancy before publication and will update this figure when confirmed against primary sources.

Before the incident, Ostium had processed more than $50 billion in cumulative trading volume. As of May 2026, the platform carried roughly $95 million in open interest, with about 91% of that concentrated in non-crypto RWA pairs.

None of the protocol's institutional backers, including General Catalyst and Jump Crypto, nor Gelato, the automation infrastructure provider whose forwarder system was central to the attack surface, had issued public statements as of filing time.


Part of a Larger Pattern

The Ostium exploit did not occur in isolation. Nine days earlier, on July 6, the DeFi protocol Summer.fi lost $6 million from its Lazy Summer USDC vault after an attacker used a $65.4 million flash loan to manipulate Curve and Morpho vault accounting. That attack was also detected by Blockaid.

As CoinDesk noted in its coverage of recent DeFi incidents, a growing pattern of exploits targets the keeper and oracle layer, the automated infrastructure DeFi protocols use to connect with off-chain data, rather than core smart contract logic.

The broader 2026 picture is difficult. By late June, 121 attacks across DeFi had produced roughly $942 million in losses, a 70% increase over the same period in 2025.

The year's largest single incident was a $292 million LayerZero bridge exploit against KelpDAO in April.

According to data cited by CCN, approximately 76% of 2026 crypto hack losses have been attributed to state-backed actors linked to the Lazarus Group.


Why This Matters for Emerging Markets

Ostium's specific product, on-chain perpetuals for gold, forex, and equity indices, is particularly relevant to users in South Asia and Africa. In India, Nigeria, Pakistan, and Kenya, access to instruments that hedge currency risk or provide exposure to international assets is either heavily regulated or practically out of reach for most retail participants. RWA perpetuals protocols were positioned as a permissionless alternative to those barriers.

That framing now faces a credibility problem. India ranks first, Nigeria ranks second, and Pakistan ranks third in the 2026 Global Crypto Adoption Index. Sub-Saharan Africa processed more than $205 billion in on-chain value between mid-2024 and mid-2025, with markets including Nigeria, Kenya, Ethiopia, and Ghana among the most active on the continent.

Retail users in these markets who deposited USDC into Ostium's OLP vault as a yield-generating strategy now face uncertainty about whether or how they will be made whole. Both India and Nigeria are also at sensitive points in their regulatory cycles, and observers suggest a high-profile exploit tied to a VC-backed protocol is likely to surface in legislative discussions about DeFi access and risk.

For developers building on Arbitrum-native infrastructure in Bangalore, Lagos, Nairobi, and Karachi, the exploit carries a direct technical warning: the Gelato automation stack is widely used across Arbitrum protocols, and private-key management for authorized oracle signers must be treated as a critical security boundary.

Ostium's Immunefi bug bounty program remains active. Verse Press will update this article as the team publishes further details.