← Back to KHAO

Oracle ·

Ostium suffers $18 million exploit as oracle attack wave continues to hit DeFi

2 min read

Compiled by KHAO Editorial — aggregated from 1 source + 2 references discovered via search. See llms.txt for citation guidance.

★ Tier-1 Source

Hacker (Pixabay)

An attacker drained approximately $18 million in USDC from Ostium's liquidity vault on Arbitrum in an oracle manipulation exploit detected by blockchain security firm Blockaid, onchain data shows.

Key facts

Summary

An attacker exploited a registered component of Ostium's price-feed automation system, submitting oracle reports with manipulated future timestamps to make losing trades appear profitable, triggering an $18 million USDC payout from the protocol's vault. The attack follows a string of similar keeper and oracle exploits in DeFi, including a $6 million drain from Summer.fi last week, highlighting persistent vulnerabilities in the automated infrastructure protocols rely on to bring real-world price data onchain. Ostium, a perpetuals exchange on Arbitrum focused on real-world assets like gold, forex, and equity indices, had raised $27.8 million in funding and processed over $50 billion in trading volume before the incident. According to Blockaid's alert, the attacker leveraged a registered PriceUpKeep forwarder, a component of Ostium's automated infrastructure, to submit oracle price reports with future-dated timestamps.

Read full article at CoinDesk →

#Oracle