Perp DEX Loses $23.75 Million in Oracle Key Exploit, Resumes Trading on July 23


On July 15, 2026, the perpetual DEX Ostium was drained of $23.75 million after an attacker obtained the private key of an oracle site and used it to manufacture fake profitable trades until the vault ran dry. Ostium temporarily suspended trading within an hour of the first malicious transaction, and after an eight-day investigation and heightened efforts, reopened the platform on July 23.

Unlike the smart contract bugs that once dominated DeFi hack headlines, this attack targeted the off-chain infrastructure that feeds prices into the protocol — the part that most audits and bug bounties are never paid to consider.

advertisement

xtb-nike-share-free

What exactly happened to Ostium?

The root cause was the private key of the compromised Oracle website and not a flaw in Ostium’s Solidity code. Security firm Blockaid, which first reported the incident, said the attacker used a registered PriceUpKeep freight forwarder to provide future-dated certified oracle reports. These reports fooled the protocol into believing that a series of trades were profitable.

From there, the attacker made approximately 20 open and closed trades through delegated actions, withdrawing recurring payments from Ostium’s main OLP (liquidity provider) vault with no exposure to the real market at all. The vault’s payment logic trusted that the rigged price inputs were real, so it settled trades that appeared profitable only because the feed itself was rigged.

Why is an oracle signing key a big deal?

The oracle signing key works like the master password for price data. When a protocol like Ostium settles perpetual trades, it relies on signed price feeds to determine who is profitable and who is not. Whoever controls the signing key can effectively tell the protocol what price it wants – bypassing the automatic checks meant to maintain the authenticity of the feed.

This is what makes this type of attack so harmful. The smart contracts did exactly what they were programmed to do; They simply acted on fraudulent instructions from someone who had access they were not supposed to have. It fits the broader 2026 pattern in which it is the largest Decentralized finance The losses are increasingly coming from the human layer and the infrastructure layer rather than buggy code.

How much was lost and where did the money go?

Ostium confirmed the exact number: 23,752,746 USDC drained from the OLP vault. Early estimates varied — Blockaid put the net loss at roughly $18 million and CertiK closer to $22 million — but the protocol’s own calculations settled on a total of roughly $23.75 million. Galaxy Research tracked eight payments to one wallet, including transfers of approximately $11.86 million, $4.49 million, and $3.59 million.

Importantly, the exploit hit shared liquidity in OLP’s public treasury, not the individual trader’s collateral. The trader’s margin remained isolated and frozen within the smart contracts throughout the downtime. However, the stolen USDC was converted into approximately 12,084 ETH and was routed through the Tornado Cash mixing service, greatly limiting the chances of recovery.

advertisement

xtb-nike-share-free

Has the Ostium hack issue been resolved?

partially. Trading resumed on July 23 at 10:00 AM ET (2:00 PM UTC), but the position was not completely closed. Here’s where things stand:

Trading has reopened in phases – only risk management and cut-order functions returned first, with remaining features gradually restored to maintain system stability. Open positions and pending orders were rolled over rather than closed during the pause period, and each position was recalculated at the live market price upon reopening, so no trader was liquidated due to price movements during the pause period.

advertisement

xtb-nike-share-free

The stolen money has not been recovered. Ostium works with and coordinates with cybersecurity companies Mandiant, ZeroShadow, and Clissionless, as well as the SEAL 911 emergency response group and law enforcement. Exchangesand bridges and issuers of stablecoins to track funds.

Compensation for affected liquidity providers is still being finalized. Ostium said it would contribute from its balance sheet alongside partners to make the affected LPs whole, but a detailed recovery plan is still pending when it reopens. So, while trading is taking place again, refunds and LP repayments remain open.

Would funding and auditing protect a protocol like this?

Not on its own. Ostium has raised about $27.8 million from major backers including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute, and GSR, and has been subject to multiple audits. None of this addressed the key management of the Oracle signatories.

Notably, Ostium’s Immunefi bug bounty range treated registered guards – including PriceUpKeep and their freight forwarders – as trusted, explicitly putting any discovery requiring a compromised or malicious guard outside the program. In other words, the specific attack surface being exploited has been declared beyond the researchers’ scope.

Compare fully MiCA regulated exchanges side by side on our comparison pageCompare fully MiCA regulated exchanges side by side on our comparison page

What does the Ostium hack mean for DeFi and RWA platforms?

It’s another reminder that securing oracle infrastructure is as important as auditing smart contracts — and arguably more so, as RWA protocols pull stocks, commodities, forex, and index prices from off-chain sources. Any protocol that relies on a single trusted signed key or the same oracle provider should ask whether it is vulnerable to the same single point of failure.

For traders, the practical advice is familiar but worth repeating: cancel unnecessary contract approvals, be careful about funds deposited in DEX vaults, and watch official channels rather than threads of rumors during an active incident.

Where can you trade cryptocurrencies on regulated platforms instead?

Incidents like the Ostium hack are a reminder of the trade-off that comes with unaudited or poorly regulated venues. In the EU, the MiCA framework now sets a common standard: as of July 1, 2026, any platform serving EU clients needs a Crypto Asset Service Provider (CASP) licence, which covers governance, client asset protection, IT security, and anti-money laundering requirements. As of late July 2026, the ESMA Register lists approximately 300 approved CASPs across the EEA, and one authorized CASP across all Member States.

If you prefer to trade on regulated, compliant platforms rather than exposing funds to an Oracle-based DEX, it’s worth comparing places by licensing status, fees, and available assets. Our broker and exchange comparison page breaks this down so you can choose a platform that actually matches how you trade.

One of the structured options is XTBa publicly listed brokerage firm that has received approval to offer spot cryptocurrency trading to EEA clients (through a Cyprus licence), alongside its own regulated brokerage products. You can open an account with XTB here.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *