Skip to main content
AVOID.NET
Ostium Protocolreviewed 2026-09-07 · 33 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Ostium Protocol against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed 5stale 1partially supported 4confirmed 236 corrections pending · 0 applied

disputed

5 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #6[disputed][awaiting moderator]in section: July 2026 Oracle Key Exploit
    All payouts were directed to a fresh externally owned account (recipient: 0x321df194...bfd9) seeded with approximately 1 ETH from ChangeNOW and Bybit prior to the attack.
    reviewerPayout recipient wallet was seeded with approximately 1 ETH from ChangeNOW and Bybit prior to the attackThe page understates the seed amount by roughly half; the wallet received 1 ETH from each of two separate exchanges (ChangeNOW and Bybit), totaling approximately 2 ETH, not approximately 1 ETH.
    Proposed correction (not yet applied)
    All payouts were directed to a fresh externally owned account (recipient: 0x321df194...bfd9) seeded with approximately 2 ETH -- 1 ETH from ChangeNOW and 1 ETH from Bybit -- prior to the attack.
  2. #15[disputed][awaiting moderator]in section: Audit Coverage Gaps and Bug Bounty Exclusions
    However, none of these reviews substantively addressed the security of off-chain oracle signer key management.
    reviewerNone of the audit reviews substantively addressed the security of off-chain oracle signer key managementThis is a blanket claim the page's own omitted evidence contradicts: at least one review (Zellic Nov 2025) directly and explicitly raised the compromised-forwarder risk that was later exploited, in writing.
    Proposed correction (not yet applied)
    However, most of these reviews did not substantively address the security of off-chain oracle signer key management, though Zellic's November 2025 review explicitly flagged the risk of a compromised forwarder in writing eight months before the exploit, and Pashov's April 2025 review included the PriceUpKeep and PrivatePriceUpKeep contracts in scope.
  3. #16[disputed][awaiting moderator]in section: Audit Coverage Gaps and Bug Bounty Exclusions
    The OstiumPrivatePriceUpKeep contract, the component through which the attack was executed, was either reviewed on an older design iteration or excluded from the most recent audit pass entirely.
    reviewerOstiumPrivatePriceUpKeep was either reviewed on an older design or excluded from the most recent audit pass entirelyThe contract was in scope in at least one 2025 review; the page's framing ('excluded entirely') is not supported. The more defensible criticism -- that in-scope review did not evaluate signer-key trust assumptions -- is a narrower and different claim than what the page states.
    Proposed correction (not yet applied)
    The OstiumPrivatePriceUpKeep contract, the component through which the attack was executed, was explicitly in scope for Pashov's April 2025 review, but that review's disclosed findings did not address oracle signer key management or trust assumptions around the keeper role.
  4. #27[disputed][awaiting moderator]in section: Protocol Response and Trading Resumption
    The team published an initial acknowledgment via X: 'We are aware of the issue with the OLP vault. We have paused all trading. The team is investigating.'
    reviewerOstium published an initial acknowledgment via X reading 'We are aware of the issue with the OLP vault...'The quoted text itself is accurate and attributable to Ostium, but the URL cited as its source (both in this section's sources[] and in sources_used) points to a different, later tweet than the one containing the quote.
    Proposed correction (not yet applied)
    https://x.com/Ostium/status/2077412452392652917
  5. #28[disputed][awaiting moderator]in the cited sources
    https://x.com/Ostium/status/2078640436688941194
    reviewerOstium published an initial acknowledgment via X reading 'We are aware of the issue with the OLP vault...' (sources_used entry)Same underlying URL mismatch as the section-level citation; flagged separately because sources_used is a distinct field that would otherwise retain the wrong link.
    Proposed correction (not yet applied)
    https://x.com/Ostium/status/2077412452392652917

stale

1 claim

The claim was accurate when written but events since have overtaken it.

  1. #30[stale][awaiting moderator]in section: Protocol Response and Trading Resumption
    A formal post-mortem was promised but had not been published as of late July 2026.
    reviewerA formal post-mortem was promised but had not been published as of late July 2026A formal post-mortem was in fact published July 29, 2026, which falls within the page's own 'late July 2026' timeframe. The compensation-plan-pending portion of this sentence remains accurate per the same source.
    Proposed correction (not yet applied)
    A formal post-mortem was published by Ostium on July 29, 2026, confirming the $23,752,746 USDC loss and attributing the attack to a compromised off-chain oracle signer.

partially supported

4 claims

The cited evidence supports part of the claim but not all of it.

  1. #3[partially supported][awaiting moderator]in the summary
    Stolen funds were converted to roughly 12,084 ETH and routed through Tornado Cash within hours, and as of late July 2026 no funds have been recovered.
    reviewerStolen funds were converted to roughly 12,084 ETH and routed through Tornado Cash within hoursThe page conflates the total ETH converted (~12,084) with the amount actually laundered through Tornado Cash; independent sources put the Tornado Cash figure at ~10,540 ETH, with the remainder still traceable in attacker-controlled wallets. The page's own section 2 (Fund Movements) separately cites the correct 10,540 figure, creating an internal inconsistency.
  2. #9[partially supported][awaiting moderator]in section: Fund Movements and Laundering
    Following the exploit, the attacker converted the stolen USDC into approximately 12,084 ETH and routed it through Tornado Cash, a cryptocurrency mixing protocol, within hours of the attack.
    reviewerAttacker converted stolen USDC into ~12,084 ETH and routed it through Tornado Cash within hoursSame overstatement as the summary: not all converted ETH was laundered through Tornado Cash. This section's next sentence correctly cites Rescana's 10,540 ETH figure, so the two sentences within the same section are internally inconsistent.
  3. #14[partially supported][awaiting moderator]in section: Audit Coverage Gaps and Bug Bounty Exclusions
    Pashov Audit Group conducted a further review in September 2025.
    reviewerPashov Audit Group conducted a further review in September 2025, and no reviews substantively addressed oracle signer key managementThe September 2025 Pashov date is accurate but the page presents it as essentially the only post-2024 review, omitting at least four other engagements that materially change the audit-coverage picture (see disputed findings below).
  4. #26[partially supported][awaiting moderator]in section: Protocol Background and Investor Backing
    Additional Series A participants included Coinbase Ventures, Wintermute Ventures, GSR, and Crucible Capital.
    reviewerAdditional Series A participants included Coinbase Ventures, Wintermute Ventures, GSR, and Crucible CapitalCoinbase Ventures, Wintermute Ventures, and Crucible Capital participation is corroborated by multiple outlets; GSR's specific participation was not independently found in the sources consulted, though it is not contradicted either.

confirmed

23 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    Ostium Protocol is an Arbitrum-based decentralized perpetuals exchange specializing in real-world asset (RWA) trading, founded in 2022 by Harvard alumni Kaledora Kiernan-Linn and Marco Antonio Ribeiro and backed by $27.8 million from General Catalyst, Jump Crypto, and Coinbase Ventures.
    reviewerOstium is an Arbitrum-based decentralized perpetuals exchange specializing in RWA tradingFounders, Arbitrum/RWA description, and funding backers are corroborated by multiple independent outlets.
  2. #2[confirmed][no action needed]in the summary
    On July 15, 2026, an attacker compromised an off-chain oracle signer private key and injected fabricated BTC/USD prices into the protocol's PriceUpKeep forwarder contract, draining $23,752,746 USDC from the liquidity provider vault through approximately 20 looped trades.
    reviewerOn July 15, 2026 an attacker compromised an oracle signer key and drained $23,752,746 USDC via ~20 looped trades through the PriceUpKeep forwarderLoss figure, mechanism, and trade-count are consistently corroborated, including by Ostium's own official statement and post-mortem.
  3. #4[confirmed][no action needed]in the summary
    and as of late July 2026 no funds have been recovered.
    reviewerNo funds recovered as of late July 2026Consistent with reporting through the end of July 2026.
  4. #5[confirmed][no action needed]in section: July 2026 Oracle Key Exploit
    In each loop, the attacker opened a BTC long position at an injected price of approximately $5,000 and immediately closed it at or near the real market price of approximately $60,000, collecting the vault-funded difference as profit.
    reviewerAttacker opened a BTC long at an injected price of ~$5,000 and closed at ~$60,000Matches cited source verbatim in substance.
  5. #7[confirmed][no action needed]in section: July 2026 Oracle Key Exploit
    Trading was paused within one hour of the first malicious transaction.
    reviewerTrading was paused within one hour of the first malicious transactionConfirmed directly by the protocol's own statement.
  6. #8[confirmed][no action needed]in section: July 2026 Oracle Key Exploit
    The protocol reopened in phases on July 23, 2026 after an eight-day security review, with open positions repriced at live market values to prevent forced liquidations.
    reviewerProtocol reopened in phases on July 23, 2026 after an eight-day security reviewDate math (July 15 to July 23 = 8 days) and reopening mechanics are corroborated.
  7. #10[confirmed][no action needed]in section: Fund Movements and Laundering
    Blockchain analytics firm Galaxy Research traced eight distinct payout transactions to the attacker's single recipient wallet, identifying transfers of $11.86 million, $4.49 million, and $3.59 million among the largest tranches.
    reviewerGalaxy Research traced eight payout transactions with tranches of $11.86M, $4.49M, and $3.59MCorroborated by independent reporting on Galaxy Research's analysis.
  8. #11[confirmed][no action needed]in section: Fund Movements and Laundering
    A separate analysis by Rescana identified approximately 10,540 ETH deposited into Tornado Cash.
    reviewerA separate analysis by Rescana identified approximately 10,540 ETH deposited into Tornado CashThis is in fact the more accurate figure for the Tornado Cash amount specifically, as opposed to the 12,084 ETH figure used elsewhere on the page as if it were the laundered amount.
  9. #12[confirmed][no action needed]in section: Fund Movements and Laundering
    Ostium pledged to contribute from its own balance sheet alongside partners to compensate affected liquidity providers, but detailed compensation timelines had not been disclosed as of the protocol's July 23 reopening.
    reviewerOstium pledged balance-sheet compensation with no detailed timeline disclosed as of July 23 reopeningConsistent with subsequent reporting.
  10. #13[confirmed][no action needed]in section: Audit Coverage Gaps and Bug Bounty Exclusions
    Zellic audited the protocol's contracts in early 2024, returning 19 findings including two rated critical, with the price-upkeep and vault contracts in scope.
    reviewerZellic audited the protocol's contracts in early 2024, returning 19 findings including two rated critical, with price-upkeep and vault contracts in scopeFinding count and severity match independent reporting.
  11. #17[confirmed][no action needed]in section: Audit Coverage Gaps and Bug Bounty Exclusions
    Critically, Ostium's Immunefi bug bounty program explicitly designated all registered keepers — including PriceUpKeep, PrivatePriceUpKeep, and TradesUpKeep — as trusted and out of scope.
    reviewerImmunefi bug bounty program designated all registered keepers (PriceUpKeep, PrivatePriceUpKeep, TradesUpKeep) as trusted and out of scopeMatches the cited primary source almost verbatim.
  12. #18[confirmed][no action needed]in section: Structural Risk: Off-Chain Oracle Key Centralization
    Because Ostium's OstiumPrivatePriceUpKeep forwarder accepted signed price reports without time-bound validation sufficient to detect future-dated timestamps, the attacker's fabricated reports appeared valid to the on-chain settlement logic.
    reviewerThe forwarder accepted signed price reports without time-bound validation sufficient to detect future-dated timestampsConsistent with independent reporting on the future-dated-timestamp mechanism.
  13. #19[confirmed][no action needed]in section: Structural Risk: Off-Chain Oracle Key Centralization
    Security firm Blockaid was the first entity to flag the exploit, through on-chain monitoring rather than a formal disclosure.
    reviewerBlockaid was the first entity to flag the exploit, through on-chain monitoring rather than a formal disclosureCorroborated across multiple outlets.
  14. #20[confirmed][no action needed]in section: Structural Risk: Off-Chain Oracle Key Centralization
    The exploit also occurred during an active wave of keeper and oracle attacks across DeFi, including a comparable $6 million exploit against Summer.fi the preceding week.
    reviewerA comparable $6 million exploit hit Summer.fi the preceding weekDollar figure and comparison to keeper/oracle attack pattern are corroborated; the 'preceding week' framing is loosely accurate (9 days, not a full 7).
  15. #21[confirmed][no action needed]in section: Protocol Background and Investor Backing
    Ostium Labs was founded in 2022 by Harvard alumni Kaledora Kiernan-Linn (CEO) and Marco Antonio Ribeiro.
    reviewerOstium Labs founded 2022 by Kaledora Kiernan-Linn (CEO) and Marco Antonio Ribeiro, both Harvard alumniFounders and Harvard affiliation confirmed; founding year not independently pinpointed beyond consistent secondary reporting.
  16. #22[confirmed][no action needed]in section: Protocol Background and Investor Backing
    Kiernan-Linn studied neuroscience at Harvard and previously trained at the Royal Danish Ballet and worked as a quantitative researcher at Bridgewater Associates.
    reviewerKiernan-Linn studied neuroscience at Harvard, trained at the Royal Danish Ballet, and worked as a quantitative researcher at Bridgewater AssociatesBallet, Harvard and Bridgewater details corroborated; the specific 'neuroscience' major was not independently pinpointed in available search snippets but is not contradicted.
  17. #23[confirmed][no action needed]in section: Protocol Background and Investor Backing
    Ribeiro is a former competitor in the International Olympiads for physics, biology, and chemistry.
    reviewerRibeiro is a former competitor in the International Olympiads for physics, biology, and chemistryConfirmed near-verbatim against source.
  18. #24[confirmed][no action needed]in section: Protocol Background and Investor Backing
    Prior to the July 2026 exploit, Ostium had processed over $50 billion in cumulative trading volume and held approximately $63 million in total value locked.
    reviewerPrior to the exploit, Ostium processed over $50 billion in cumulative volume and held ~$63 million TVLConfirmed across multiple independent outlets.
  19. #25[confirmed][no action needed]in section: Protocol Background and Investor Backing
    The protocol raised $27.8 million in total funding, including a $20 million Series A co-led by General Catalyst and Jump Crypto announced in December 2025, and a previously undisclosed $4 million strategic round.
    reviewerOstium raised $27.8 million total, including a $20 million Series A (Dec 2025) and a previously undisclosed $4 million strategic roundFunding breakdown matches independent reporting closely.
  20. #29[confirmed][no action needed]in section: Protocol Response and Trading Resumption
    Ostium confirmed that trader collateral and open positions were held in separate contracts and were not directly affected by the vault drain.
    reviewerTrader collateral and open positions were held in separate contracts and unaffected by the vault drainDirectly confirmed by Ostium's own official statement.
  21. #31[confirmed][no action needed]in section: Protocol Response and Trading Resumption
    The protocol's detailed compensation plan for affected liquidity providers remained pending.
    reviewerThe protocol's detailed compensation plan for affected liquidity providers remained pendingRemained accurate through the end of July 2026 per the post-mortem coverage.
  22. #32[confirmed][no action needed]in section: Broader DeFi Oracle Security Context
    Over $840 million was reported stolen across DeFi in the first five months of 2026 alone.
    reviewerOver $840 million was reported stolen across DeFi in the first five months of 2026Figure corroborated by independent industry reporting.
  23. #33[confirmed][no action needed]in section: Broader DeFi Oracle Security Context
    The Ostium incident was detected by blockchain security firm Blockaid through on-chain monitoring and was reported by CoinDesk on July 15, 2026.
    reviewerThe Ostium incident was detected by Blockaid through on-chain monitoring and was reported by CoinDesk on July 15, 2026Detection and same-day reporting are both corroborated.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.