Skip to main content
AVOID.NET

Fact-check findings

What an automated fact-checker found when it re-read Ostium Protocol — Oracle Signer Key Compromise (July 2026) against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed 1partially supported 2confirmed 161 correction pending · 0 applied

disputed

1 claim

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #15[disputed][awaiting moderator]in the summary
    This incident is classified as the second-largest individual exploit of July 2026 and fits the dominant H1 2026 pattern of privileged-key infrastructure attacks, which caused an estimated $790 million in losses across the first half of the year.
    reviewerThis incident is classified as the second-largest individual exploit of July 2026.No inline source is cited for this specific ranking claim. Two independent monthly hack reports for July 2026 both rank Ostium third-largest, behind the Coldcard hardware-wallet exploit and the AFX Bridge compromise (which occurred July 22, one week after Ostium).
    Proposed correction (not yet applied)
    This incident is one of the largest individual exploits of July 2026, ranking behind the Coldcard hardware-wallet exploit and the AFX Bridge private-key compromise, and fits the dominant H1 2026 pattern of privileged-key infrastructure attacks, which caused an estimated $790 million in losses across the first half of the year.

partially supported

2 claims

The cited evidence supports part of the claim but not all of it.

  1. #13[partially supported][awaiting moderator]in section: Protocol Background and Funding
    As of the time of the exploit, Ostium reported cumulative trading volume exceeding $50 billion and maintained a TVL in the OLP vault of approximately $32.7 million.
    reviewerOstium reported cumulative trading volume exceeding $50 billion as of the time of the exploit.The $50B figure is independently verifiable from an official April 2026 Ostium press release (not among the sources cited for this section), but conflicts with a $33B figure reported by Crypto Briefing on the day of the exploit itself. The $50B figure is likely closer to accurate given its official sourcing, but the page does not cite the source that actually supports this number.
  2. #16[partially supported][awaiting moderator]in section: Broader Context: H1 2026 Privileged-Key Attack Wave
    Private key compromises and infrastructure breaches — the category into which the Ostium exploit falls — accounted for an estimated $790 million of those losses, or approximately 74% of stolen value by dollar amount.
    reviewerPrivate key compromises and infrastructure breaches accounted for an estimated $790 million of H1 2026 losses, or approximately 74% of stolen value by dollar amount.The general finding -- that roughly three-quarters of H1 2026 crypto hack losses stemmed from privileged-key/infrastructure compromise -- is well corroborated across multiple independent reports (72-76% range, $700-790M range depending on total used). However, the specific $790 million and 74% figures do not appear in either of the two sources actually cited for this section; they are closer to figures found in other, uncited reporting (e.g., TRM Labs' 76%/~$738M).

confirmed

16 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    On July 15, 2026, Ostium Protocol, an Arbitrum-based on-chain perpetuals exchange focused on real-world assets, suffered a $23,752,746 USDC loss after an attacker obtained or compromised the private key of an authorized off-chain oracle signer.
    reviewerOn July 15, 2026, Ostium suffered a $23,752,746 USDC loss from an oracle signer key compromise via a PriceUpKeep forwarder, opening BTC longs at ~$5,000 and closing near $60,000, across eight transactions in under six minutes.Core facts of the incident are consistently corroborated across independent, credible reporting and the primary rekt.news technical writeup.
  2. #2[confirmed][no action needed]in section: Incident Overview
    Ostium Protocol's OLP (Ostium Liquidity Provider) vault on the Arbitrum network was drained of 23,752,746 USDC through a five-minute-and-twenty-nine-second attack window between 14:18 and 14:23 UTC.
    reviewerThe attack window ran between 14:18 and 14:23 UTC, a five-minute-and-twenty-nine-second window.One secondary outlet (Blockonomi/BitRss) rounds the window to 14:18-14:24 (~6 minutes), but the founder's own public statement and rekt.news match the page's figure exactly.
  3. #3[confirmed][no action needed]in section: Incident Overview
    The confirmed loss figure of $23,752,746 USDC emerged from on-chain accounting; initial estimates from security firms ranged from approximately $18 million (Blockaid) to $24 million (PeckShield).
    reviewerInitial estimates from security firms ranged from approximately $18 million (Blockaid) to $24 million (PeckShield), before the confirmed figure of $23,752,746 emerged.Matches independent reporting; a third firm (Cyvers) also produced an intermediate estimate not mentioned on the page, which is a minor omission but not an inaccuracy.
  4. #4[confirmed][no action needed]in section: Technical Attack Mechanism
    An initial test transaction using $100 USDC yielded an $897.80 payout, confirming the exploit path. Twenty-five seconds later, the attacker executed the main drain transaction (0x359f8c05b86a4409d60cfba02084334313fd94b19f74a294fb7fc4ea7d4870e0), in which a single atomic batch of twenty alternating open-close cycles — each opening a leveraged long at $5,000 and closing at the real market price near $60,000 — extracted $11,862,444 USDC in one block.
    reviewerThe exploited signer address (0x38110430184c22d93c30b3e67b9af98d5d0ab8bd), PrivatePriceUpKeep contract (0xB71ec9eBD8145daCaCF6724363143cb5667A3d36), Trading contract (0x6D0bA1f9996DBD8885827e1b2e8f6593e7702411), and attacker address (0x321Df194646029e7A6193Ea05573d4B9c398bfD9) as stated, along with the test/main transaction hashes and amounts.Verified address-by-address and transaction-by-transaction against the cited technical source.
  5. #5[confirmed][no action needed]in section: Technical Attack Mechanism
    The stolen USDC was subsequently converted to approximately 12,084 ETH via KyberSwap at an average execution price of approximately $1,966 per ETH, then distributed across at least 30 attacker-controlled wallets. On the day of the exploit, 10,540 ETH was deposited into Tornado Cash, obscuring subsequent fund flows and representing approximately 83% of the proceeds by value.
    reviewerThe stolen USDC was converted to approximately 12,084 ETH via KyberSwap at an average execution price of approximately $1,966 per ETH, and 10,540 ETH (~83% of proceeds) was routed to Tornado Cash the same day.A minor rounding discrepancy exists across sources (12,080 vs 12,084 ETH); the page's own cited primary source (rekt.news) matches the page's figure exactly, so this is not treated as an error.
  6. #6[confirmed][no action needed]in section: Technical Attack Mechanism
    Galaxy Research and other on-chain analysts traced eight payments to that wallet.
    reviewerGalaxy Research and other on-chain analysts traced eight payments to the primary exploiter wallet.Independently corroborated.
  7. #7[confirmed][no action needed]in section: Prior Audit Warnings and Security Gaps
    Ostium accumulated six security audits across three firms — Zellic, ThreeSigma, and Pashov Audit Group — spanning more than two years, with the final audit completed in January 2026, approximately six months before the exploit.
    reviewerOstium accumulated six security audits across three firms (Zellic, ThreeSigma, Pashov Audit Group) spanning more than two years, with the final audit completed in January 2026.A separate primary source (the Pashov Audit Group GitHub README) lists only three Pashov dates (2025-01-21, 2025-04-06, 2025-08-22) with no January 2026 entry, which could not be fully reconciled; however both the page's own cited source and Ostium's official docs corroborate the January 2026 date, so this is treated as confirmed rather than disputed.
  8. #8[confirmed][no action needed]in section: Prior Audit Warnings and Security Gaps
    An earlier Zellic audit from 2024 identified 19 findings including two critical issues; that engagement's scope explicitly excluded 'key custody' and 'infrastructure relating to the project,' which is precisely where the exploited PriceUpKeep operator resided.
    reviewerAn earlier Zellic audit from 2024 identified 19 findings including two critical issues; that engagement's scope explicitly excluded 'key custody' and 'infrastructure relating to the project.'Verified against independent summary of the Zellic report itself.
  9. #9[confirmed][no action needed]in section: Prior Audit Warnings and Security Gaps
    Pashov Audit Group's September 2025 review covered only trading-engine contracts and either reviewed OstiumPrivatePriceUpKeep under an outdated design or excluded it entirely.
    reviewerPashov Audit Group's September 2025 review covered only trading-engine contracts and either reviewed OstiumPrivatePriceUpKeep under an outdated design or excluded it entirely.Directly confirmed against the primary Pashov audit document itself, which matches the page's description of scope exactly.
  10. #10[confirmed][no action needed]in section: Prior Audit Warnings and Security Gaps
    Following the incident, investigators noted that Ostium's public documentation stated audits found 'no critical vulnerabilities,' which did not accurately reflect the content of the underlying audit reports.
    reviewerOstium's public documentation stated audits found 'no critical vulnerabilities,' which did not accurately reflect the underlying audit reports.Confirmed.
  11. #11[confirmed][no action needed]in section: Prior Audit Warnings and Security Gaps
    The protocol's bug bounty program additionally classified registered keepers and forwarders as 'assumed to be trusted and operating correctly,' explicitly removing compromised-keeper scenarios from eligible scope, which discouraged external researchers from investigating the exact attack surface that was ultimately exploited.
    reviewerOstium's bug bounty program classified registered keepers and forwarders as 'assumed to be trusted and operating correctly,' explicitly excluding compromised-keeper scenarios from scope.Directly confirmed against the primary Immunefi scope document.
  12. #12[confirmed][no action needed]in section: Impact on Liquidity Providers and Trader Funds
    The vault's USDC balance declined by approximately 72%, from roughly $32.7 million to approximately $9 million.
    reviewerThe vault's USDC balance declined by approximately 72%, from roughly $32.7 million to approximately $9 million.Confirmed against cited source.
  13. #14[confirmed][no action needed]in section: Protocol Background and Funding
    Ostium Protocol is an Arbitrum-based on-chain perpetuals exchange founded by two former Harvard classmates, publicly identified as Kaledora and Marco, with backgrounds at Harvard and Bridgewater Associates.
    reviewerOstium Protocol was founded by two former Harvard classmates, publicly identified as Kaledora and Marco, with backgrounds at Harvard and Bridgewater Associates; raised a $20M Series A in December 2025 co-led by General Catalyst and Jump Crypto, bringing total funding to ~$27.8 million.Confirmed.
  14. #17[confirmed][no action needed]in section: Broader Context: H1 2026 Privileged-Key Attack Wave
    This pattern was exemplified by several large exploits in the first half of the year, including the Drift exchange compromise, in which alleged North Korean state-linked hackers conducted a months-long social engineering campaign before obtaining privileged access.
    reviewerThe Drift exploit involved alleged North Korean state-linked hackers conducting a months-long social engineering campaign before obtaining privileged access.Confirmed via independent research; no inline source cited on the page for this specific comparison.
  15. #18[confirmed][no action needed]in section: Broader Context: H1 2026 Privileged-Key Attack Wave
    Ostium's incident also parallels the March 2026 Resolv exploit, in which a single privileged role was used to bypass on-chain monetary limits, as noted by DeFi Prime's analysis.
    reviewerThe March 2026 Resolv exploit involved a single privileged role used to bypass on-chain monetary limits.Confirmed via independent research.
  16. #19[confirmed][no action needed]in section: Prior Audit Warnings and Security Gaps
    Section 4.8 of that report explicitly described risks arising from a compromised forwarder, stating: 'By design, forwarders can cancel any order or action,' and adding: 'These concerns are not a complete enumeration of the potential issues that can arise from a compromised forwarder.'
    reviewerZellic Section 4.8 explicitly described risks arising from a compromised forwarder, stating 'By design, forwarders can cancel any order or action' and that the enumerated concerns were not exhaustive.Confirmed.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.