Particle.news
Download on the App Store

Ostium Loses $18 Million After Oracle Manipulation Drains Vault

Blockaid says attackers used a registered PriceUpKeep forwarder to submit future-dated oracle reports that fabricated trading profits, emptying a large share of the protocol's liquidity.

Overview

  • Security firm Blockaid reported that attackers abused Ostium’s PriceUpKeep forwarder to submit future-dated or falsified oracle reports that made losing trades appear profitable and triggered roughly $18 million in USDC payouts.
  • The protocol paused all trading and froze trader funds and open positions while investigators work to confirm exact loss figures and whether a compromised oracle signer key played a role.
  • On-chain traces show the attacker ran repeated trading loops, converted some stolen USDC into ETH through Kyber Network, and dispersed funds across multiple wallets after the drain.
  • The theft removed roughly 28–33% of Ostium’s liquidity from a vault that held about $63 million, threatening liquidity providers despite the protocol’s $27.8 million in disclosed funding and institutional backers.
  • The exploit echoes a string of 2026 attacks that target off-chain oracle and keeper systems, raising pressure on protocols to strengthen signer key custody, off-chain validation logic, and automation controls.