Overview
- Security firm Blockaid reported that attackers abused Ostium’s PriceUpKeep forwarder to submit future-dated or falsified oracle reports that made losing trades appear profitable and triggered roughly $18 million in USDC payouts.
- The protocol paused all trading and froze trader funds and open positions while investigators work to confirm exact loss figures and whether a compromised oracle signer key played a role.
- On-chain traces show the attacker ran repeated trading loops, converted some stolen USDC into ETH through Kyber Network, and dispersed funds across multiple wallets after the drain.
- The theft removed roughly 28–33% of Ostium’s liquidity from a vault that held about $63 million, threatening liquidity providers despite the protocol’s $27.8 million in disclosed funding and institutional backers.
- The exploit echoes a string of 2026 attacks that target off-chain oracle and keeper systems, raising pressure on protocols to strengthen signer key custody, off-chain validation logic, and automation controls.