← Ostium Protocol — Oracle Signer Key Compromise (July 2026)1 decision on this page
Audit log
Every state-changing event for Ostium Protocol — Oracle Signer Key Compromise (July 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-02 17:24:10ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
Dj9aTzuDhU2E…iEQ3Epf2sha256 → base58
verifying row…canonical bytes (31235 B) ▸
{"actor":"system:backfill","investigation_id":"b67351d6-4938-413c-aa54-0ba5284676b1","kind":"publish","page_slug":"ostium-protocol-oracle-signer-key-compromise-july-2026","published_at":"2026-08-02T17:24:10.597Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Ostium Protocol — Oracle Signer Key Compromise (July 2026)","sections":[{"content":"On July 15, 2026, Ostium Protocol's OLP (Ostium Liquidity Provider) vault on the Arbitrum network was drained of 23,752,746 USDC through a five-minute-and-twenty-nine-second attack window between 14:18 and 14:23 UTC. The attack did not exploit a vulnerability in Ostium's audited smart-contract code. Instead, an attacker obtained valid credentials for two privileged components of the protocol's off-chain price infrastructure: an authorized oracle signer key and a registered PriceUpKeep forwarder. The exploit was detected mid-execution by blockchain security firm Blockaid. All trading contracts were paused within approximately sixty minutes of the first exploit transaction. Kaledora, the Ostium co-founder, published a public acknowledgment the same day. Ostium's protocol reopened on July 23, 2026, following an eight-day hardening and migration effort. The confirmed loss figure of $23,752,746 USDC emerged from on-chain accounting; initial estimates from security firms ranged from approximately $18 million (Blockaid) to $24 million (PeckShield).","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Ostium suspends trading after OLP vault exploit drains up to $23.7M in USDC — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/ostium-suspends-trading-olp-vault-exploit/"},{"credibility":1,"name":"Ostium loses $18 million in oracle attack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi"},{"credibility":2,"name":"Ostium Post-Mortem Confirms $23.75M Vault Loss, Blames Off-Chain Signer — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/30/ostium-post-mortem-confirms-23-75m-vault-loss-blames-off-chain-signer/"},{"credibility":2,"name":"Ostium Hack: Perp DEX Loses $23.75M in Oracle Key Exploit, Resumes Trading July 23 — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/ostium-hack-oracle-exploit-arbitrum/"},{"credibility":2,"name":"Ostium — Rekt News","type":"research","url":"https://rekt.news/ostium-rekt"}]},{"content":"Ostium uses a custom pull-oracle architecture in which an authorized signer keys price reports that are then pushed on-chain by a registered Gelato-powered PriceUpKeep forwarder. The OstiumVerifier contract performs ECDSA signature recovery and checks whether the signer is in its approved-signer registry, but investigators found that the contract did not enforce price-plausibility bounds, timestamp validity windows, replay protection, or multi-source cross-referencing. The attacker held or had obtained the private key for an oracle signer address (0x38110430184c22d93c30b3e67b9af98d5d0ab8bd) that had been legitimately registered in Ostium's verifier contract since February 14, 2026 — 151 days before the exploit. The attacker used this key to sign fabricated price reports showing Bitcoin at approximately $5,000, then submitted those reports through the registered PrivatePriceUpKeep contract (0xB71ec9eBD8145daCaCF6724363143cb5667A3d36) against Ostium's Trading contract (0x6D0bA1f9996DBD8885827e1b2e8f6593e7702411). The protocol's vault treated these signed reports as authoritative. An initial test transaction using $100 USDC yielded an $897.80 payout, confirming the exploit path. Twenty-five seconds later, the attacker executed the main drain transaction (0x359f8c05b86a4409d60cfba02084334313fd94b19f74a294fb7fc4ea7d4870e0), in which a single atomic batch of twenty alternating open-close cycles — each opening a leveraged long at $5,000 and closing at the real market price near $60,000 — extracted $11,862,444 USDC in one block. Six additional standalone drain transactions followed, bringing total proceeds to $23,752,746 USDC. All payouts were directed to a single primary exploiter address: 0x321Df194646029e7A6193Ea05573d4B9c398bfD9. Galaxy Research and other on-chain analysts traced eight payments to that wallet. The stolen USDC was subsequently converted to approximately 12,084 ETH via KyberSwap at an average execution price of approximately $1,966 per ETH, then distributed across at least 30 attacker-controlled wallets. On the day of the exploit, 10,540 ETH was deposited into Tornado Cash, obscuring subsequent fund flows and representing approximately 83% of the proceeds by value.","heading":"Technical Attack Mechanism","severity":"critical","sources":[{"credibility":2,"name":"Ostium — Rekt News (full technical breakdown with contract addresses and transaction hashes)","type":"research","url":"https://rekt.news/ostium-rekt"},{"credibility":2,"name":"Inside the Ostium Exploit: How False Prices Unlocked a $23.75M Heist — Blockonomi","type":"news_article","url":"https://blockonomi.com/inside-the-ostium-exploit-how-false-prices-unlocked-a-23-75m-heist"},{"credibility":2,"name":"Prices from the future fooled this crypto oracle into sending millions to wrong wallet — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/how-prices-from-the-future-fooled-a-crypto-oracle-into-paying-out-up-to-24-million/"},{"credibility":2,"name":"Ostium DeFi Platform Breach — Rescana (attacker address and transaction sequence)","type":"research","url":"https://www.rescana.com/post/ostium-defi-platform-breach-23-75-million-stolen-in-off-chain-oracle-attack-and-credential-compromise"},{"credibility":2,"name":"The Ostium Exploit: How a Fake $5,000 Bitcoin Price Drained a Perp DEX — DeFi Prime","type":"news_article","url":"https://defiprime.com/ostium-exploit"},{"credibility":2,"name":"Ostium Vault Exploiter Routes 10,540 ETH to Tornado Cash — CryptoNews.net","type":"on_chain","url":"https://cryptonews.net/news/security/33160177/"}]},{"content":"Ostium accumulated six security audits across three firms — Zellic, ThreeSigma, and Pashov Audit Group — spanning more than two years, with the final audit completed in January 2026, approximately six months before the exploit. In November 2025, Zellic conducted a second engagement reviewing upgraded trading contracts ahead of Ostium's Jump Liquidity Upgrade. Section 4.8 of that report explicitly described risks arising from a compromised forwarder, stating: 'By design, forwarders can cancel any order or action,' and adding: 'These concerns are not a complete enumeration of the potential issues that can arise from a compromised forwarder.' According to post-incident analysis by Rekt News, Ostium addressed only the specific collateral-removal example Zellic illustrated rather than the broader architectural category of risk. Pashov Audit Group's September 2025 review covered only trading-engine contracts and either reviewed OstiumPrivatePriceUpKeep under an outdated design or excluded it entirely. An earlier Zellic audit from 2024 identified 19 findings including two critical issues; that engagement's scope explicitly excluded 'key custody' and 'infrastructure relating to the project,' which is precisely where the exploited PriceUpKeep operator resided. Following the incident, investigators noted that Ostium's public documentation stated audits found 'no critical vulnerabilities,' which did not accurately reflect the content of the underlying audit reports. The protocol's bug bounty program additionally classified registered keepers and forwarders as 'assumed to be trusted and operating correctly,' explicitly removing compromised-keeper scenarios from eligible scope, which discouraged external researchers from investigating the exact attack surface that was ultimately exploited.","heading":"Prior Audit Warnings and Security Gaps","severity":"high","sources":[{"credibility":2,"name":"Ostium — Rekt News (audit history and Zellic warning)","type":"research","url":"https://rekt.news/ostium-rekt"},{"credibility":2,"name":"Zellic Audit Reports — Ostium","type":"research","url":"https://reports.zellic.io/publications/ostium"},{"credibility":2,"name":"The Ostium Exploit: How a Fake $5,000 Bitcoin Price Drained a Perp DEX — DeFi Prime (Pashov audit gap)","type":"news_article","url":"https://defiprime.com/ostium-exploit"},{"credibility":2,"name":"Explained: The Ostium Hack (July 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-ostium-hack-july-2026"},{"credibility":3,"name":"Ostium $23.75M Exploit: Not a Smart Contract Bug, an Oracle Key Compromise — Ainvest","type":"news_article","url":"https://www.ainvest.com/news/ostium-23-75m-exploit-smart-contract-bug-oracle-key-compromise-structural-risk-reveals-2607/"}]},{"content":"The OLP vault is funded by liquidity providers (LPs) who deposit USDC in exchange for OLP tokens and a share of trading fees. Ostium's architecture holds trader collateral in a separate contract from the OLP vault. As a result of this design, trader collateral was not affected by the exploit and open positions remained frozen at prices as of the time trading was suspended. The entire $23,752,746 loss was absorbed by OLP vault depositors. The vault's USDC balance declined by approximately 72%, from roughly $32.7 million to approximately $9 million. Ostium suspended new OLP deposits while processing withdrawals according to its settlement cycle. As of the time of the July 30, 2026 post-mortem publication, Ostium had committed to contributing from its own balance sheet alongside new and existing partners to support affected liquidity providers, but had not disclosed the specific structure, timeline, or percentage coverage of any compensation plan. A recovery plan for LPs was stated to be published separately.","heading":"Impact on Liquidity Providers and Trader Funds","severity":"high","sources":[{"credibility":2,"name":"Ostium Post-Mortem Confirms $23.75M Vault Loss, Blames Off-Chain Signer — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/30/ostium-post-mortem-confirms-23-75m-vault-loss-blames-off-chain-signer/"},{"credibility":2,"name":"Ostium suspends trading after OLP vault exploit — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/ostium-suspends-trading-olp-vault-exploit/"},{"credibility":2,"name":"Ostium Loses $23.7M After Off-Chain Price Oracle Breach — Metaverse Post","type":"news_article","url":"https://mpost.io/ostium-loses-23-7m-after-off-chain-price-oracle-breach-recovers-trading-post-migration/"},{"credibility":3,"name":"Ostium Prepares Trading Relaunch After $24M Cyber Attack — Namecoin News","type":"news_article","url":"https://www.namecoinnews.com/ostium-to-relaunch-after-24-exploit-recovery/"}]},{"content":"Blockaid detected the exploit during execution and published the first public alert, attributing the attack to 'a registered PriceUpKeep forwarder and future-dated authorized oracle reports.' Within approximately sixty minutes of the first exploit transaction, Ostium's engineering team coordinated to pause all trading contracts. Trading remained suspended for eight days. Ostium founder Kaledora issued a public statement on July 15 acknowledging the breach: 'This morning, between 14:18-14:23 UTC, Ostium experienced a security issue leading to a loss of funds from the public OLP vault. Our team identified the issue within minutes and immediately began taking steps to contain it, including coordinating to pause trading contracts within the hour.' A follow-up statement confirmed that positions remained open and frozen, and that a technical post-mortem and outline of the path forward would be published in the coming days. On July 18, 2026, Ostium characterized the attack as involving a party who 'compromised off-chain infrastructure related to the system that feeds prices into the protocol,' and submitted manipulated price reports designed to appear legitimate. The protocol migrated to a new production environment with multi-party approvals, enhanced off-chain security controls, and deauthorized and isolated affected systems with external cybersecurity support. Ostium engaged on-chain tracing firms zeroShadow, Collisionless, and Inca Digital to track stolen funds. Trading resumed on July 23, 2026. As of the July 30 post-mortem publication, Ostium confirmed the loss at $23,752,746 USDC and attributed the root cause unambiguously to the compromised off-chain signer, ruling out any smart-contract code vulnerability or governance multisig compromise.","heading":"Post-Exploit Response and Remediation","severity":"medium","sources":[{"credibility":2,"name":"Ostium Post-Mortem Confirms $23.75M Vault Loss, Blames Off-Chain Signer — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/30/ostium-post-mortem-confirms-23-75m-vault-loss-blames-off-chain-signer/"},{"credibility":2,"name":"Ostium to Resume Trading on July 23 After $18M Arbitrum Exploit — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/22/ostium-to-resume-trading-on-july-23-after-18m-arbitrum-exploit/"},{"credibility":2,"name":"Ostium Confirms $23.75M Hack Originated from Off-Chain Infrastructure Breach — TheCryptoUpdates","type":"news_article","url":"https://www.thecryptoupdates.com/ostium-confirms-23-75m-hack-originated-from-off-chain-infrastructure-breach/"},{"credibility":1,"name":"Hackers steal $23.7 million in crypto from Ostium in off-chain attack — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/hackers-steal-237-million-in-crypto-from-ostium-in-off-chain-attack/"},{"credibility":1,"name":"Ostium blames off-chain breach for $24 million exploit, rules out smart contract flaw — The Block","type":"news_article","url":"https://www.theblock.co/post/410122/ostium-post-mortem-exploit"}]},{"content":"The Ostium exploit is consistent with the dominant attack category of H1 2026. According to Blockaid's H1 2026 report, crypto hacks reached a record high by incident count, with total losses exceeding $1 billion across the period. Separate reporting by Immunefi placed H1 2026 losses at $972 million across 207 incidents. Private key compromises and infrastructure breaches — the category into which the Ostium exploit falls — accounted for an estimated $790 million of those losses, or approximately 74% of stolen value by dollar amount. This pattern was exemplified by several large exploits in the first half of the year, including the Drift exchange compromise, in which alleged North Korean state-linked hackers conducted a months-long social engineering campaign before obtaining privileged access. Ostium's incident also parallels the March 2026 Resolv exploit, in which a single privileged role was used to bypass on-chain monetary limits, as noted by DeFi Prime's analysis. The Ostium case highlights a structural risk present across multiple DeFi protocols in 2026: pull-oracle architectures that concentrate price-reporting authority in small sets of authorized keys create single points of failure that audits scoped to smart contracts are structurally unable to surface.","heading":"Broader Context: H1 2026 Privileged-Key Attack Wave","severity":"high","sources":[{"credibility":1,"name":"Crypto hack losses fall below $1 billion in H1 2026 despite record attack volume — The Block (Immunefi report)","type":"research","url":"https://www.theblock.co/post/407707/crypto-hack-losses-fall-below-1-billion-in-h1-2026-even-as-attack-volume-hits-record-immunefi"},{"credibility":1,"name":"Crypto hacks hit record high in H1 2026 as losses top $1 billion, Blockaid says — The Block","type":"research","url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"},{"credibility":2,"name":"DeFi Hacks 2026: $840M+ Lost and the Attack That Changed Everything — AltFins","type":"research","url":"https://altfins.com/blog/defi-hacks-2026/"},{"credibility":1,"name":"Crypto Hacks 2026: CertiK CEO On $1.3 Billion In Losses — Forbes","type":"news_article","url":"https://www.forbes.com/sites/boazsobrado/2026/07/17/fewer-but-far-more-surgical-crypto-hacks-hit-13-billion-in-2026/"},{"credibility":2,"name":"Compromised Oracle Key Drains $18M From Ostium, Exposing DeFi's Off-Chain Blind Spot — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/320708/20260716/compromised-oracle-key-drains-18m-ostium-exposing-defis-off-chain-blind-spot.htm"},{"credibility":2,"name":"The Ostium Exploit — DeFi Prime (Resolv parallel)","type":"news_article","url":"https://defiprime.com/ostium-exploit"}]},{"content":"Ostium Protocol is an Arbitrum-based on-chain perpetuals exchange founded by two former Harvard classmates, publicly identified as Kaledora and Marco, with backgrounds at Harvard and Bridgewater Associates. The protocol specializes in perpetual swaps for real-world assets (RWAs) including commodities, equities, equity indices, and foreign exchange pairs, offering leverage of up to 200x. As of the time of the exploit, Ostium reported cumulative trading volume exceeding $50 billion and maintained a TVL in the OLP vault of approximately $32.7 million. In December 2025, Ostium raised a $20 million Series A co-led by General Catalyst and Jump Crypto, bringing total funding to approximately $27.8 million. Other disclosed investors include Coinbase Ventures, Crucible Capital, LocalGlobe, Susquehanna (SIG), GSR, and Wintermute Ventures. Ostium launched its mainnet vault in 2024.","heading":"Protocol Background and Funding","severity":"low","sources":[{"credibility":1,"name":"Jump Crypto, General Catalyst Lead $20M Series A for Ostium — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2025/12/03/ostium-raises-usd20m-series-a-led-by-general-catalyst-jump-crypto-to-put-tradfi-perps-onchain"},{"credibility":1,"name":"Ostium Raises $20 Million Series A from General Catalyst and Jump Crypto — BusinessWire","type":"official","url":"https://www.businesswire.com/news/home/20251203478893/en/Ostium-Raises-$20-Million-Series-A-from-General-Catalyst-Jump-Crypto-to-Bring-Global-Markets-Onchain"},{"credibility":2,"name":"Jump Crypto co-leads $20M Series A for Ostium for RWA perpetuals — Ledger Insights","type":"news_article","url":"https://www.ledgerinsights.com/jump-crypto-co-leads-20m-series-a-for-ostium-for-rwa-perpetuals/"}]},{"content":"Recovery of the stolen $23,752,746 USDC is considered highly unlikely based on the laundering path taken. The stolen USDC was converted to approximately 12,084 ETH via KyberSwap within hours of the exploit. Approximately 10,540 ETH — representing roughly 83% of the proceeds — was deposited into Tornado Cash before the end of July 15, 2026. Additional 10 ETH deposits into Tornado Cash were detected in subsequent days. The remaining approximately $4 million in ETH was distributed across roughly 30 attacker-controlled wallets. On-chain tracing efforts were engaged by zeroShadow, Collisionless, and Inca Digital on behalf of Ostium. No attacker identity or attribution to a known threat actor group had been publicly established as of the post-mortem date. No law enforcement announcements or asset freezes had been publicly reported as of late July 2026.","heading":"Fund Recovery Outlook","severity":"high","sources":[{"credibility":2,"name":"Ostium Vault Exploiter Routes 10,540 ETH to Tornado Cash — CryptoNews.net","type":"on_chain","url":"https://cryptonews.net/news/security/33160177/"},{"credibility":2,"name":"Ostium — Rekt News (fund flow breakdown)","type":"research","url":"https://rekt.news/ostium-rekt"},{"credibility":2,"name":"Ostium DeFi Platform Breach — Rescana (ETH conversion and wallet distribution)","type":"research","url":"https://www.rescana.com/post/ostium-defi-platform-breach-23-75-million-stolen-in-off-chain-oracle-attack-and-credential-compromise"},{"credibility":2,"name":"Ostium Hack: $24M Oracle Exploit, Fund Movements, and AML Crypto Analysis — AMLCrypto","type":"on_chain","url":"https://amlcrypto.io/blog/vzlom-ostium-s-manupyliazieu-oraculom"}]}],"sources_used":[{"credibility":2,"name":"Ostium — Rekt News","type":"research","url":"https://rekt.news/ostium-rekt"},{"credibility":2,"name":"Ostium Post-Mortem Confirms $23.75M Vault Loss, Blames Off-Chain Signer — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/30/ostium-post-mortem-confirms-23-75m-vault-loss-blames-off-chain-signer/"},{"credibility":1,"name":"Ostium loses $18 million in oracle attack — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi"},{"credibility":1,"name":"Hackers steal $23.7 million in crypto from Ostium in off-chain attack — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/hackers-steal-237-million-in-crypto-from-ostium-in-off-chain-attack/"},{"credibility":1,"name":"Ostium blames off-chain breach for $24 million exploit, rules out smart contract flaw — The Block","type":"news_article","url":"https://www.theblock.co/post/410122/ostium-post-mortem-exploit"},{"credibility":2,"name":"Ostium suspends trading after OLP vault exploit drains up to $23.7M in USDC — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/ostium-suspends-trading-olp-vault-exploit/"},{"credibility":2,"name":"Another DeFi Exploit: Perp DEX Ostium Loses $18 Million in Oracle Attack — Decrypt","type":"news_article","url":"https://decrypt.co/373566/defi-exploit-ostium-oracle-hack"},{"credibility":2,"name":"Inside the Ostium Exploit: How False Prices Unlocked a $23.75M Heist — Blockonomi","type":"news_article","url":"https://blockonomi.com/inside-the-ostium-exploit-how-false-prices-unlocked-a-23-75m-heist"},{"credibility":2,"name":"Prices from the future fooled this crypto oracle into sending millions to wrong wallet — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/how-prices-from-the-future-fooled-a-crypto-oracle-into-paying-out-up-to-24-million/"},{"credibility":2,"name":"Ostium DeFi Platform Breach — Rescana","type":"research","url":"https://www.rescana.com/post/ostium-defi-platform-breach-23-75-million-stolen-in-off-chain-oracle-attack-and-credential-compromise"},{"credibility":2,"name":"The Ostium Exploit: How a Fake $5,000 Bitcoin Price Drained a Perp DEX — DeFi Prime","type":"news_article","url":"https://defiprime.com/ostium-exploit"},{"credibility":2,"name":"Explained: The Ostium Hack (July 2026) — Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-ostium-hack-july-2026"},{"credibility":3,"name":"Ostium $23.75M Exploit: Not a Smart Contract Bug, an Oracle Key Compromise — Ainvest","type":"news_article","url":"https://www.ainvest.com/news/ostium-23-75m-exploit-smart-contract-bug-oracle-key-compromise-structural-risk-reveals-2607/"},{"credibility":2,"name":"Ostium Vault Exploiter Routes 10,540 ETH to Tornado Cash — CryptoNews.net","type":"on_chain","url":"https://cryptonews.net/news/security/33160177/"},{"credibility":2,"name":"Ostium Hack: $24M Oracle Exploit, Fund Movements, and AML Crypto Analysis — AMLCrypto","type":"on_chain","url":"https://amlcrypto.io/blog/vzlom-ostium-s-manupyliazieu-oraculom"},{"credibility":1,"name":"Crypto hack losses fall below $1 billion in H1 2026 despite record attack volume — The Block (Immunefi)","type":"research","url":"https://www.theblock.co/post/407707/crypto-hack-losses-fall-below-1-billion-in-h1-2026-even-as-attack-volume-hits-record-immunefi"},{"credibility":1,"name":"Crypto hacks hit record high in H1 2026 as losses top $1 billion, Blockaid says — The Block","type":"research","url":"https://www.theblock.co/post/409944/crypto-hacks-hit-record-high-in-h1-2026-as-losses-top-1-billion-blockaid-says"},{"credibility":1,"name":"Crypto Hacks 2026: CertiK CEO On $1.3 Billion In Losses — Forbes","type":"news_article","url":"https://www.forbes.com/sites/boazsobrado/2026/07/17/fewer-but-far-more-surgical-crypto-hacks-hit-13-billion-in-2026/"},{"credibility":1,"name":"Jump Crypto, General Catalyst Lead $20M Series A for Ostium — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2025/12/03/ostium-raises-usd20m-series-a-led-by-general-catalyst-jump-crypto-to-put-tradfi-perps-onchain"},{"credibility":1,"name":"Ostium Raises $20 Million Series A — BusinessWire (official press release)","type":"official","url":"https://www.businesswire.com/news/home/20251203478893/en/Ostium-Raises-$20-Million-Series-A-from-General-Catalyst-Jump-Crypto-to-Bring-Global-Markets-Onchain"},{"credibility":2,"name":"Zellic Audit Reports — Ostium","type":"research","url":"https://reports.zellic.io/publications/ostium"},{"credibility":2,"name":"Ostium to Resume Trading on July 23 — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/22/ostium-to-resume-trading-on-july-23-after-18m-arbitrum-exploit/"},{"credibility":2,"name":"Ostium Hack: Perp DEX Loses $23.75M in Oracle Key Exploit, Resumes Trading July 23 — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/ostium-hack-oracle-exploit-arbitrum/"},{"credibility":2,"name":"Ostium Loses $23.7M After Off-Chain Price Oracle Breach — Metaverse Post","type":"news_article","url":"https://mpost.io/ostium-loses-23-7m-after-off-chain-price-oracle-breach-recovers-trading-post-migration/"},{"credibility":2,"name":"DeFi Hacks 2026: $840M+ Lost — AltFins","type":"research","url":"https://altfins.com/blog/defi-hacks-2026/"}],"summary":"On July 15, 2026, Ostium Protocol, an Arbitrum-based on-chain perpetuals exchange focused on real-world assets, suffered a $23,752,746 USDC loss after an attacker obtained or compromised the private key of an authorized off-chain oracle signer. Using the stolen credentials, the attacker submitted fabricated but validly signed price reports through a registered PriceUpKeep forwarder, enabling them to open leveraged Bitcoin positions at an artificial price of approximately $5,000 and close them near the real market price of $60,000, extracting the spread from the protocol's OLP liquidity vault across eight transactions in under six minutes. The stolen USDC was subsequently converted to approximately 12,084 ETH and 10,540 ETH was routed through Tornado Cash within hours, severely curtailing recovery prospects. This incident is classified as the second-largest individual exploit of July 2026 and fits the dominant H1 2026 pattern of privileged-key infrastructure attacks, which caused an estimated $790 million in losses across the first half of the year.","timeline":[{"date":"2024-01-01","event":"Ostium Protocol launched its mainnet OLP vault on Arbitrum. Exact launch date within 2024 not confirmed; year sourced from reporting.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/ostium-suspends-trading-olp-vault-exploit/"},{"date":"2025-11-01","event":"Zellic completed a second security engagement for Ostium, covering upgraded trading contracts ahead of the Jump Liquidity Upgrade. Section 4.8 of the report explicitly flagged risks arising from a compromised forwarder, warning the enumerated concerns were not exhaustive.","source":"Rekt News / Zellic Audit Reports","source_url":"https://reports.zellic.io/publications/ostium"},{"date":"2025-12-03","event":"Ostium announced a $20 million Series A co-led by General Catalyst and Jump Crypto, bringing total funding to approximately $27.8 million.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2025/12/03/ostium-raises-usd20m-series-a-led-by-general-catalyst-jump-crypto-to-put-tradfi-perps-onchain"},{"date":"2026-01-01","event":"Ostium's final pre-exploit smart-contract audit was completed. Exact date within January 2026 not confirmed in sourced reporting.","source":"Rekt News","source_url":"https://rekt.news/ostium-rekt"},{"date":"2026-02-14","event":"The oracle signer address (0x38110430184c22d93c30b3e67b9af98d5d0ab8bd) that was later used in the exploit was legitimately registered in Ostium's verifier contract — 151 days before the exploit.","source":"Rekt News","source_url":"https://rekt.news/ostium-rekt"},{"date":"2026-07-15","event":"Attack window opened at 14:18 UTC. An initial test transaction using $100 USDC yielded an $897.80 payout. Twenty-five seconds later, the main drain transaction (0x359f8c05b86a4409d60cfba02084334313fd94b19f74a294fb7fc4ea7d4870e0) extracted $11,862,444 USDC in a single atomic batch. Six additional drain transactions followed. Total drain: 23,752,746 USDC. Attack window closed at 14:23 UTC.","source":"Rekt News / Blockonomi / CryptoTimes","source_url":"https://rekt.news/ostium-rekt"},{"date":"2026-07-15","event":"Blockaid detected the exploit in progress and published a public alert attributing it to a registered PriceUpKeep forwarder and future-dated oracle reports. Ostium paused all trading contracts within approximately sixty minutes of the first exploit transaction.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi"},{"date":"2026-07-15","event":"Attacker converted stolen USDC to approximately 12,084 ETH via KyberSwap at an average price of approximately $1,966 per ETH and deposited 10,540 ETH into Tornado Cash before the end of the day.","source":"CryptoNews.net / Rekt News","source_url":"https://cryptonews.net/news/security/33160177/"},{"date":"2026-07-15","event":"Kaledora, Ostium co-founder, published a public statement acknowledging the breach, confirming the 14:18–14:23 UTC attack window, and stating the team had identified the issue within minutes.","source":"CryptoTimes / CoinGabbar","source_url":"https://www.coingabbar.com/en/crypto-currency-news/ostium-hack-2026-oracle-exploit-defi-24m-usdc-arbitrum"},{"date":"2026-07-18","event":"Ostium published an update characterizing the incident as stemming from a compromise of 'off-chain infrastructure related to the system that feeds prices into the protocol,' ruling out smart-contract vulnerabilities or multisig compromise.","source":"The Block","source_url":"https://www.theblock.co/post/410122/ostium-post-mortem-exploit"},{"date":"2026-07-23","event":"Ostium resumed trading following migration to a new production environment with multi-party approvals, enhanced off-chain security controls, and deauthorization of affected systems.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/22/ostium-to-resume-trading-on-july-23-after-18m-arbitrum-exploit/"},{"date":"2026-07-30","event":"Ostium published a full post-mortem confirming the $23,752,746 USDC loss and attributing it unambiguously to the compromised off-chain oracle signer. Compensation plan for LPs was described as forthcoming but details not disclosed.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/07/30/ostium-post-mortem-confirms-23-75m-vault-loss-blames-off-chain-signer/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 8c86e9ba-debe-4159-8ba6-2bea58cba932
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.