The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol.
According to an update from the platform yesterday, the attacker submitted illegitimate price reports disguised as valid ones, then rapidly opened and closed large positions to generate artificial profits.
Trader collateral was held in a separate contract and was not affected, while existing positions remain open, the company clarified.
Ostium is a decentralized trading platform built on the Arbitrum finance-native blockchain scaling solution, allowing users to speculate on the prices of traditional and crypto assets directly from a cryptocurrency wallet.
Prices are supplied to the protocol via external data feeds, while trades are settled in USDC, a cryptocurrency designed to maintain a 1:1 peg to the US dollar.
The company first notified its community about the incident on July 16, when it stated that trading had to be paused due to a security incident.
The announcement stated that the relevant authorities were notified and that the movement of stolen funds was being tracked, although no additional details were provided at the time.
In its latest update, Ostium describes the incident as an attack on off-chain infrastructure that feeds Ostium prices, which were manipulated to make the attackers a profit by stealing from the liquidity provider’s vault.
According to blockchain security firm PeckShieldAlert, the exploiter swapped the stolen USDC for 12,080 Ethereum and then deposited 10,540 Ethereum to TornadoCash, a cryptocurrency mixer.
Money trace from the incident
Source: PeckShieldAlert
Ostium has clarified that trading amounts for leveraged positions are stored in a separate smart contract and were not impacted by this incident.
The collateral posted by ordinary traders was not stolen, and any existing long and short positions were not closed or liquidated.
These positions remain recorded, but are effectively frozen now, as all trading in the platform was paused within 60 minutes of the first exploit transaction.
The company is now working to secure the affected infrastructure and determine a path forward for liquidity providers.
Notice on the trading page of the Ostium website
Source: BleepingComputer.com
Five days after the incident, trading on Ostium is still paused and the company promised to provide at least 24 hours' notice before operations resume, at which point positions will be marked to the reopening price.
Also, Ostium has promised to provide a post-mortem analysis with technical details in the coming days.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.