Skip to main content
Sign in
Ostium1 decision on this page

Audit log

Every state-changing event for Ostium: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions carry three independent witnesses — the original source, an Internet Archive snapshot taken at submission time, and a Solana memo signed by our publicly-disclosed publisher key.

  1. #1publishby system:backfill
    2026-07-22 01:47:46Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    HxafuoDaiTfK…Hqt1Ejqusha256 → base58
    verifying row…
    canonical bytes (14875 B) ▸
    {"actor":"system:backfill","investigation_id":"ccef10a3-7a88-4030-bd90-e1212c1b2913","kind":"publish","page_slug":"ostium","published_at":"2026-07-22T01:47:46.193Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Ostium","sections":[{"content":"On July 15, 2026, blockchain security firm Blockaid detected and publicly disclosed an exploit against Ostium's public Ostium Liquidity Provider (OLP) vault. According to Blockaid, an attacker compromised the private key of an oracle signer and used it to submit authorized but future-dated price reports through a registered PriceUpKeep Forwarder, fabricating artificial trading profit. The attacker allegedly reported a Bitcoin price as low as $5,000 against a real market price near $60,000, opened leveraged positions at the fabricated low price, then closed them at the real market price to capture the spread. Security firm Halborn described the attack as looped: the attacker allegedly alternated between initiating a trade and manipulating the price via the OstiumPrivatePriceUpKeep function across roughly ten to twenty iterations, compounding margin each round for an estimated 900% profit per round. Loss estimates vary by source: Blockaid and CoinDesk cited approximately $18 million in USDC drained from the OLP vault (roughly 28% of Ostium's ~$63 million TVL at the time); other outlets, including Cryptobriefing and CoinGabbar, cited estimates as high as $22-24 million when including affected vault exposure; independent on-chain observers cited by The Defiant put the figure closer to $11.86 million. Ostium had not published its own official loss accounting as of the most recent reporting reviewed.","heading":"The July 15, 2026 Oracle Exploit","severity":"critical","sources":[{"credibility":2,"name":"Blockaid uncovers $18M exploit that forces Ostium trading halt","type":"news_article","url":"https://crypto.news/blockaid-uncovers-18m-exploit-that-forces-ostium-halt/"},{"credibility":1,"name":"Ostium loses $18 million in oracle attack that gamed its own price-feed infrastructure - CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi"},{"credibility":2,"name":"Explained: The Ostium Hack (July 2026) - Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-ostium-hack-july-2026"},{"credibility":2,"name":"Ostium Halts Trading After Oracle Exploit Drains up to $18M from Vault - The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/ostium-halts-trading-after-oracle-exploit-drains-up-to-usd18m-from-vault"},{"credibility":2,"name":"Ostium Hack: How $24M Drain From Arbitrum? Will Users Recover Funds? - CoinGabbar","type":"news_article","url":"https://www.coingabbar.com/en/crypto-currency-news/ostium-hack-2026-oracle-exploit-defi-24m-usdc-arbitrum"}]},{"content":"The component exploited in the attack, PriceUpKeep and its related keeper infrastructure (PrivatePriceUpKeep, TradesUpKeep, and their forwarders), was explicitly carved out of Ostium's bug bounty program hosted on Immunefi. The program's published scope states: \"All registered keepers (PriceUpKeep, PrivatePriceUpKeep, TradesUpKeep) and their forwarders are assumed to be trusted and operating correctly. Issues requiring a compromised or malicious keeper are out of scope.\" This meant independent security researchers had no financial incentive to probe the exact attack surface that was ultimately compromised. Multiple outlets, including Halborn and crypto.news, characterized this exclusion as a critical design and process oversight, noting that conventional smart-contract audits are structured to catch code-level bugs but are not designed to catch compromise of privileged, trusted off-chain infrastructure such as oracle signing keys.","heading":"Bug Bounty Scope Excluded the Exploited Component","severity":"high","sources":[{"credibility":1,"name":"Ostium Bug Bounties Scope - Immunefi","type":"official","url":"https://immunefi.com/bug-bounty/ostium/scope/"},{"credibility":2,"name":"Explained: The Ostium Hack (July 2026) - Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-ostium-hack-july-2026"},{"credibility":2,"name":"Blockaid uncovers $18M exploit that forces Ostium trading halt","type":"news_article","url":"https://crypto.news/blockaid-uncovers-18m-exploit-that-forces-ostium-halt/"}]},{"content":"Reporting indicates Ostium's price-feed infrastructure relied on a third-party automation network, Gelato, to push oracle prices onchain via keeper bots, a dependency CoinDesk's reporting described as central to the vulnerability. The precise method by which the attacker obtained the oracle signer's private key had not been disclosed by Ostium or independent investigators as of the most recent reporting reviewed. This places the incident in a broader pattern flagged by CoinDesk of oracle- and privileged-key-compromise attacks hitting DeFi protocols in mid-2026, including a reported $6 million exploit at Summer.fi roughly a week prior to the Ostium incident. Analysts characterized these incidents as reflecting a shift in DeFi exploit patterns away from smart-contract code bugs toward compromise of privileged off-chain signing infrastructure and automation/keeper systems.","heading":"Oracle Key Compromise and Third-Party Dependency","severity":"high","sources":[{"credibility":1,"name":"Ostium loses $18 million in oracle attack that gamed its own price-feed infrastructure - CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi"},{"credibility":2,"name":"Compromised Oracle Key Drains $18M From Ostium, Exposing DeFi's Off-Chain Blind Spot - Tech Times","type":"news_article","url":"https://www.techtimes.com/articles/320708/20260716/compromised-oracle-key-drains-18m-ostium-exposing-defis-off-chain-blind-spot.htm"}]},{"content":"Ostium halted all trading within approximately one hour of the exploit being detected on July 15, 2026. The team stated publicly: \"We are aware of the issue with the OLP vault. We have paused all trading. The team is investigating,\" and later added that \"All trader funds and open positions are currently preserved as-is (frozen)... The team is actively investigating with relevant security experts.\" According to The Defiant, Ostium said it was working with law enforcement, the volunteer security group SEAL 911, and third-party cybersecurity teams, and promised continued disclosures. As of the most recent reporting reviewed, Ostium had not published a definitive loss total, a root-cause postmortem, or a concrete reimbursement plan or timeline for affected liquidity providers, and it remained unclear whether the stolen funds could be recovered or the attacker identified. The attacker reportedly converted the stolen assets into ETH following the exploit, a common laundering step that complicates fund recovery.","heading":"Incident Response and Transparency","severity":"medium","sources":[{"credibility":2,"name":"Ostium Halts Trading After Oracle Exploit Drains up to $18M from Vault - The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/ostium-halts-trading-after-oracle-exploit-drains-up-to-usd18m-from-vault"},{"credibility":2,"name":"Ostium Hack: How $24M Drain From Arbitrum? Will Users Recover Funds? - CoinGabbar","type":"news_article","url":"https://www.coingabbar.com/en/crypto-currency-news/ostium-hack-2026-oracle-exploit-defi-24m-usdc-arbitrum"},{"credibility":2,"name":"Blockaid uncovers $18M exploit that forces Ostium trading halt","type":"news_article","url":"https://crypto.news/blockaid-uncovers-18m-exploit-that-forces-ostium-halt/"}]},{"content":"Ostium was founded by Harvard alumni Kaledora Kiernan-Linn and Marco Antonio Ribeiro as an Arbitrum-based perpetuals exchange offering onchain exposure to real-world assets including commodities, FX, indices, and metals via a quote-based pricing model. The company raised a $20 million Series A co-led by General Catalyst and Jump Crypto, disclosed in December 2025, plus a previously unannounced $4 million strategic round, bringing total funding to approximately $27.8 million and an implied valuation of around $250 million. Prior to the July 2026 exploit, Ostium reported having processed roughly $25-50 billion in cumulative trading volume (figures vary by source and reporting date), including several billion dollars in metals trading. Before the hack, protocol TVL was reported at approximately $63 million. This funding and volume profile indicates Ostium was a reasonably well-capitalized and institutionally backed protocol at the time of the exploit, which several outlets noted made the bug-bounty scope gap and reliance on a single trusted oracle-signing key more notable as a governance and risk-management failure rather than a sign of an unfunded or fly-by-night operation.","heading":"Background: Founding, Funding, and Prior Standing","severity":"low","sources":[{"credibility":2,"name":"Ostium Raises $20 Million Series A from General Catalyst & Jump Crypto - BusinessWire","type":"news_article","url":"https://www.businesswire.com/news/home/20251203478893/en/Ostium-Raises-$20-Million-Series-A-from-General-Catalyst-Jump-Crypto-to-Bring-Global-Markets-Onchain"},{"credibility":2,"name":"Harvard alumni-founded Ostium lands $24 million in fresh funding - The Block","type":"news_article","url":"https://www.theblock.co/post/381241/harvard-alumni-founded-ostium-lands-24-million-in-fresh-funding-to-scale-onchain-perpetuals-for-rwas"},{"credibility":1,"name":"Jump Crypto, General Catalyst Lead $20M Series A for Onchain Tradfi Perps Firm Ostium - CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2025/12/03/ostium-raises-usd20m-series-a-led-by-general-catalyst-jump-crypto-to-put-tradfi-perps-onchain"}]}],"sources_used":[{"credibility":1,"name":"Ostium loses $18 million in oracle attack that gamed its own price-feed infrastructure - CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi"},{"credibility":2,"name":"Explained: The Ostium Hack (July 2026) - Halborn","type":"research","url":"https://www.halborn.com/blog/post/explained-the-ostium-hack-july-2026"},{"credibility":2,"name":"Blockaid uncovers $18M exploit that forces Ostium trading halt - crypto.news","type":"news_article","url":"https://crypto.news/blockaid-uncovers-18m-exploit-that-forces-ostium-halt/"},{"credibility":2,"name":"Ostium Halts Trading After Oracle Exploit Drains up to $18M from Vault - The Defiant","type":"news_article","url":"https://thedefiant.io/news/hacks/ostium-halts-trading-after-oracle-exploit-drains-up-to-usd18m-from-vault"},{"credibility":2,"name":"Compromised Oracle Key Drains $18M From Ostium, Exposing DeFi's Off-Chain Blind Spot - Tech Times","type":"news_article","url":"https://www.techtimes.com/articles/320708/20260716/compromised-oracle-key-drains-18m-ostium-exposing-defis-off-chain-blind-spot.htm"},{"credibility":1,"name":"Ostium Bug Bounties Scope - Immunefi","type":"official","url":"https://immunefi.com/bug-bounty/ostium/scope/"},{"credibility":2,"name":"Ostium Hack: How $24M Drain From Arbitrum? Will Users Recover Funds? - CoinGabbar","type":"news_article","url":"https://www.coingabbar.com/en/crypto-currency-news/ostium-hack-2026-oracle-exploit-defi-24m-usdc-arbitrum"},{"credibility":2,"name":"Ostium Raises $20 Million Series A from General Catalyst & Jump Crypto - BusinessWire","type":"news_article","url":"https://www.businesswire.com/news/home/20251203478893/en/Ostium-Raises-$20-Million-Series-A-from-General-Catalyst-Jump-Crypto-to-Bring-Global-Markets-Onchain"},{"credibility":2,"name":"Harvard alumni-founded Ostium lands $24 million in fresh funding - The Block","type":"news_article","url":"https://www.theblock.co/post/381241/harvard-alumni-founded-ostium-lands-24-million-in-fresh-funding-to-scale-onchain-perpetuals-for-rwas"},{"credibility":1,"name":"Jump Crypto, General Catalyst Lead $20M Series A for Onchain Tradfi Perps Firm Ostium - CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2025/12/03/ostium-raises-usd20m-series-a-led-by-general-catalyst-jump-crypto-to-put-tradfi-perps-onchain"}],"summary":"Ostium is an Arbitrum-based decentralized perpetuals exchange, founded by Harvard alumni Kaledora Kiernan-Linn and Marco Antonio Ribeiro, that offers leveraged exposure to real-world assets such as commodities, FX, and indices. On July 15, 2026, the protocol lost an estimated $18-24 million after an attacker compromised an oracle signer's private key and pushed forged, future-dated BTC/USD price reports through a component (PriceUpKeep) that Ostium's own bug bounty program had explicitly excluded from scrutiny. Ostium halted trading within roughly an hour of detection, but as of the most recent reporting the protocol had not published a final loss figure, root-cause postmortem, or reimbursement plan for affected liquidity providers.","timeline":[{"date":"2025-12-03","event":"Ostium announces a $20 million Series A co-led by General Catalyst and Jump Crypto, plus a previously undisclosed $4 million strategic round, bringing total funding to approximately $27.8 million.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2025/12/03/ostium-raises-usd20m-series-a-led-by-general-catalyst-jump-crypto-to-put-tradfi-perps-onchain"},{"date":"2026-07-15","event":"An attacker allegedly compromises an Ostium oracle signer's private key and submits forged, future-dated BTC/USD price reports (as low as $5,000 vs a real price near $60,000) through the PriceUpKeep Forwarder component, extracting an estimated $18-24 million from the OLP vault via looped trades.","source":"Blockaid / CoinDesk / Halborn","source_url":"https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi"},{"date":"2026-07-15","event":"Blockaid detects and publicly discloses the exploit; Ostium halts all trading within roughly one hour, stating trader funds and open positions are frozen and preserved as-is.","source":"crypto.news / The Defiant","source_url":"https://crypto.news/blockaid-uncovers-18m-exploit-that-forces-ostium-halt/"},{"date":"2026-07-16","event":"Follow-up coverage highlights that the exploited PriceUpKeep component was explicitly excluded from Ostium's Immunefi bug bounty scope, and that the attacker converted stolen funds to ETH.","source":"Tech Times / Halborn","source_url":"https://www.techtimes.com/articles/320708/20260716/compromised-oracle-key-drains-18m-ostium-exposing-defis-off-chain-blind-spot.htm"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 38015bf8-8cf8-4e3b-9cac-d552a21e303f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.