Fact-check findings
What an automated fact-checker found when it re-read Ostium Protocol — Oracle Signer Key Compromise (July 2026) against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
1 claimThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #15[disputed][awaiting moderator]in the summary
“This incident is classified as the second-largest individual exploit of July 2026 and fits the dominant H1 2026 pattern of privileged-key infrastructure attacks, which caused an estimated $790 million in losses across the first half of the year.”
reviewerThis incident is classified as the second-largest individual exploit of July 2026.No inline source is cited for this specific ranking claim. Two independent monthly hack reports for July 2026 both rank Ostium third-largest, behind the Coldcard hardware-wallet exploit and the AFX Bridge compromise (which occurred July 22, one week after Ostium).Proposed correction (not yet applied)This incident is one of the largest individual exploits of July 2026, ranking behind the Coldcard hardware-wallet exploit and the AFX Bridge private-key compromise, and fits the dominant H1 2026 pattern of privileged-key infrastructure attacks, which caused an estimated $790 million in losses across the first half of the year.
partially supported
2 claimsThe cited evidence supports part of the claim but not all of it.
- #13[partially supported][awaiting moderator]in section: Protocol Background and Funding
“As of the time of the exploit, Ostium reported cumulative trading volume exceeding $50 billion and maintained a TVL in the OLP vault of approximately $32.7 million.”
reviewerOstium reported cumulative trading volume exceeding $50 billion as of the time of the exploit.The $50B figure is independently verifiable from an official April 2026 Ostium press release (not among the sources cited for this section), but conflicts with a $33B figure reported by Crypto Briefing on the day of the exploit itself. The $50B figure is likely closer to accurate given its official sourcing, but the page does not cite the source that actually supports this number. - #16[partially supported][awaiting moderator]in section: Broader Context: H1 2026 Privileged-Key Attack Wave
“Private key compromises and infrastructure breaches — the category into which the Ostium exploit falls — accounted for an estimated $790 million of those losses, or approximately 74% of stolen value by dollar amount.”
reviewerPrivate key compromises and infrastructure breaches accounted for an estimated $790 million of H1 2026 losses, or approximately 74% of stolen value by dollar amount.The general finding -- that roughly three-quarters of H1 2026 crypto hack losses stemmed from privileged-key/infrastructure compromise -- is well corroborated across multiple independent reports (72-76% range, $700-790M range depending on total used). However, the specific $790 million and 74% figures do not appear in either of the two sources actually cited for this section; they are closer to figures found in other, uncited reporting (e.g., TRM Labs' 76%/~$738M).
confirmed
16 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“On July 15, 2026, Ostium Protocol, an Arbitrum-based on-chain perpetuals exchange focused on real-world assets, suffered a $23,752,746 USDC loss after an attacker obtained or compromised the private key of an authorized off-chain oracle signer.”
reviewerOn July 15, 2026, Ostium suffered a $23,752,746 USDC loss from an oracle signer key compromise via a PriceUpKeep forwarder, opening BTC longs at ~$5,000 and closing near $60,000, across eight transactions in under six minutes.Core facts of the incident are consistently corroborated across independent, credible reporting and the primary rekt.news technical writeup. - #2[confirmed][no action needed]in section: Incident Overview
“Ostium Protocol's OLP (Ostium Liquidity Provider) vault on the Arbitrum network was drained of 23,752,746 USDC through a five-minute-and-twenty-nine-second attack window between 14:18 and 14:23 UTC.”
reviewerThe attack window ran between 14:18 and 14:23 UTC, a five-minute-and-twenty-nine-second window.One secondary outlet (Blockonomi/BitRss) rounds the window to 14:18-14:24 (~6 minutes), but the founder's own public statement and rekt.news match the page's figure exactly. - #3[confirmed][no action needed]in section: Incident Overview
“The confirmed loss figure of $23,752,746 USDC emerged from on-chain accounting; initial estimates from security firms ranged from approximately $18 million (Blockaid) to $24 million (PeckShield).”
reviewerInitial estimates from security firms ranged from approximately $18 million (Blockaid) to $24 million (PeckShield), before the confirmed figure of $23,752,746 emerged.Matches independent reporting; a third firm (Cyvers) also produced an intermediate estimate not mentioned on the page, which is a minor omission but not an inaccuracy. - #4[confirmed][no action needed]in section: Technical Attack Mechanism
“An initial test transaction using $100 USDC yielded an $897.80 payout, confirming the exploit path. Twenty-five seconds later, the attacker executed the main drain transaction (0x359f8c05b86a4409d60cfba02084334313fd94b19f74a294fb7fc4ea7d4870e0), in which a single atomic batch of twenty alternating open-close cycles — each opening a leveraged long at $5,000 and closing at the real market price near $60,000 — extracted $11,862,444 USDC in one block.”
reviewerThe exploited signer address (0x38110430184c22d93c30b3e67b9af98d5d0ab8bd), PrivatePriceUpKeep contract (0xB71ec9eBD8145daCaCF6724363143cb5667A3d36), Trading contract (0x6D0bA1f9996DBD8885827e1b2e8f6593e7702411), and attacker address (0x321Df194646029e7A6193Ea05573d4B9c398bfD9) as stated, along with the test/main transaction hashes and amounts.Verified address-by-address and transaction-by-transaction against the cited technical source. - #5[confirmed][no action needed]in section: Technical Attack Mechanism
“The stolen USDC was subsequently converted to approximately 12,084 ETH via KyberSwap at an average execution price of approximately $1,966 per ETH, then distributed across at least 30 attacker-controlled wallets. On the day of the exploit, 10,540 ETH was deposited into Tornado Cash, obscuring subsequent fund flows and representing approximately 83% of the proceeds by value.”
reviewerThe stolen USDC was converted to approximately 12,084 ETH via KyberSwap at an average execution price of approximately $1,966 per ETH, and 10,540 ETH (~83% of proceeds) was routed to Tornado Cash the same day.A minor rounding discrepancy exists across sources (12,080 vs 12,084 ETH); the page's own cited primary source (rekt.news) matches the page's figure exactly, so this is not treated as an error. - #6[confirmed][no action needed]in section: Technical Attack Mechanism
“Galaxy Research and other on-chain analysts traced eight payments to that wallet.”
reviewerGalaxy Research and other on-chain analysts traced eight payments to the primary exploiter wallet.Independently corroborated. - #7[confirmed][no action needed]in section: Prior Audit Warnings and Security Gaps
“Ostium accumulated six security audits across three firms — Zellic, ThreeSigma, and Pashov Audit Group — spanning more than two years, with the final audit completed in January 2026, approximately six months before the exploit.”
reviewerOstium accumulated six security audits across three firms (Zellic, ThreeSigma, Pashov Audit Group) spanning more than two years, with the final audit completed in January 2026.A separate primary source (the Pashov Audit Group GitHub README) lists only three Pashov dates (2025-01-21, 2025-04-06, 2025-08-22) with no January 2026 entry, which could not be fully reconciled; however both the page's own cited source and Ostium's official docs corroborate the January 2026 date, so this is treated as confirmed rather than disputed. - #8[confirmed][no action needed]in section: Prior Audit Warnings and Security Gaps
“An earlier Zellic audit from 2024 identified 19 findings including two critical issues; that engagement's scope explicitly excluded 'key custody' and 'infrastructure relating to the project,' which is precisely where the exploited PriceUpKeep operator resided.”
reviewerAn earlier Zellic audit from 2024 identified 19 findings including two critical issues; that engagement's scope explicitly excluded 'key custody' and 'infrastructure relating to the project.'Verified against independent summary of the Zellic report itself. - #9[confirmed][no action needed]in section: Prior Audit Warnings and Security Gaps
“Pashov Audit Group's September 2025 review covered only trading-engine contracts and either reviewed OstiumPrivatePriceUpKeep under an outdated design or excluded it entirely.”
reviewerPashov Audit Group's September 2025 review covered only trading-engine contracts and either reviewed OstiumPrivatePriceUpKeep under an outdated design or excluded it entirely.Directly confirmed against the primary Pashov audit document itself, which matches the page's description of scope exactly. - #10[confirmed][no action needed]in section: Prior Audit Warnings and Security Gaps
“Following the incident, investigators noted that Ostium's public documentation stated audits found 'no critical vulnerabilities,' which did not accurately reflect the content of the underlying audit reports.”
reviewerOstium's public documentation stated audits found 'no critical vulnerabilities,' which did not accurately reflect the underlying audit reports.Confirmed. - #11[confirmed][no action needed]in section: Prior Audit Warnings and Security Gaps
“The protocol's bug bounty program additionally classified registered keepers and forwarders as 'assumed to be trusted and operating correctly,' explicitly removing compromised-keeper scenarios from eligible scope, which discouraged external researchers from investigating the exact attack surface that was ultimately exploited.”
reviewerOstium's bug bounty program classified registered keepers and forwarders as 'assumed to be trusted and operating correctly,' explicitly excluding compromised-keeper scenarios from scope.Directly confirmed against the primary Immunefi scope document. - #12[confirmed][no action needed]in section: Impact on Liquidity Providers and Trader Funds
“The vault's USDC balance declined by approximately 72%, from roughly $32.7 million to approximately $9 million.”
reviewerThe vault's USDC balance declined by approximately 72%, from roughly $32.7 million to approximately $9 million.Confirmed against cited source. - #14[confirmed][no action needed]in section: Protocol Background and Funding
“Ostium Protocol is an Arbitrum-based on-chain perpetuals exchange founded by two former Harvard classmates, publicly identified as Kaledora and Marco, with backgrounds at Harvard and Bridgewater Associates.”
reviewerOstium Protocol was founded by two former Harvard classmates, publicly identified as Kaledora and Marco, with backgrounds at Harvard and Bridgewater Associates; raised a $20M Series A in December 2025 co-led by General Catalyst and Jump Crypto, bringing total funding to ~$27.8 million.Confirmed. - #17[confirmed][no action needed]in section: Broader Context: H1 2026 Privileged-Key Attack Wave
“This pattern was exemplified by several large exploits in the first half of the year, including the Drift exchange compromise, in which alleged North Korean state-linked hackers conducted a months-long social engineering campaign before obtaining privileged access.”
reviewerThe Drift exploit involved alleged North Korean state-linked hackers conducting a months-long social engineering campaign before obtaining privileged access.Confirmed via independent research; no inline source cited on the page for this specific comparison. - #18[confirmed][no action needed]in section: Broader Context: H1 2026 Privileged-Key Attack Wave
“Ostium's incident also parallels the March 2026 Resolv exploit, in which a single privileged role was used to bypass on-chain monetary limits, as noted by DeFi Prime's analysis.”
reviewerThe March 2026 Resolv exploit involved a single privileged role used to bypass on-chain monetary limits.Confirmed via independent research. - #19[confirmed][no action needed]in section: Prior Audit Warnings and Security Gaps
“Section 4.8 of that report explicitly described risks arising from a compromised forwarder, stating: 'By design, forwarders can cancel any order or action,' and adding: 'These concerns are not a complete enumeration of the potential issues that can arise from a compromised forwarder.'”
reviewerZellic Section 4.8 explicitly described risks arising from a compromised forwarder, stating 'By design, forwarders can cancel any order or action' and that the enumerated concerns were not exhaustive.Confirmed.