Ostium Confirms July 15 Exploit Came From an Off‑Chain Infrastructure Breach

Bybit
Ledger


TL;DR

  • Exploit Origin: Ostium confirmed the July 15 incident stemmed from unauthorized off‑chain access that enabled fraudulent BTC‑USD price reports.
  • Attack Method: The attacker tested with a 100 USDC position, then executed larger batches that drained 23.75 million USDC from the OLP vault.
  • Post‑Incident Actions: Automated monitoring limited further withdrawals, trading resumed July 23, and a recovery plan for liquidity providers is being prepared.

The team behind Ostium has released new details on the July 15 exploit that drained 23.75 million USDC from its public OLP vault, confirming that the incident originated from a breach of off‑chain infrastructure rather than any flaw in the protocol’s smart contracts or multisigs. The update, published Wednesday, outlines how the attacker gained unauthorized access to off‑chain systems and used that foothold to push fraudulent BTC‑USD price reports into the protocol.

Off‑Chain Access Enabled Fraudulent Price Reports

According to the post‑mortem, the attacker leveraged unauthorized access to Ostium’s off‑chain infrastructure to submit manipulated price data. This allowed them to generate artificial trading profits from the OLP vault. The team emphasized that the breach occurred entirely off‑chain and that its investigation found no evidence of issues in the protocol’s smart‑contract logic or governance multisigs.

The attacker used forwarder paths already recognized by the protocol. They began with a small test, opening a 100 USDC position that produced roughly 897.8 USDC in artificial profit. After confirming the method worked, they executed a larger batch that transferred 11.9 million USDC to a beneficiary wallet, followed by six additional standalone cycles. In total, the vault lost 23.75 million USDC.

okex

Monitoring Systems Limited Further DamageMonitoring Systems Limited Further Damage

Monitoring Systems Limited Further Damage

Ostium said its automated monitoring tools detected the suspicious activity and prevented further withdrawals. The protocol has since migrated to a new production environment with strengthened security controls. Trading resumed on July 23, and the team noted that trader collateral and user margin remained intact within the protocol’s trading contracts throughout the incident. A recovery plan for liquidity providers is currently being finalized and will be shared separately, according to the update.

Context Around the Exploit

The breach occurred two months after Ostium partnered with Nasdaq to support equity perpetual products using the exchange operator’s market data. At that time, the protocol reported more than $50 billion in cumulative trading volume, underscoring the scale at which it was operating before the exploit.



Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*