Key Takeaways
- Off-chain infrastructure vulnerability enabled the July 15 security breach at Ostium.
- Attackers extracted 23.75 million USDC from the platform’s OLP vault.
- Manipulated BTC-USD price data generated fake trading gains for the exploiter.
- Smart contract code and protocol multisig wallets showed no vulnerabilities.
- User margin and trader collateral stayed protected within trading contracts.
Ostium has identified an off-chain infrastructure vulnerability as the root cause of the July 15 security incident that resulted in 23.75 million USDC being extracted from its OLP vault. The perpetuals trading platform confirmed that smart contract vulnerabilities and multisig wallet compromises played no role in the attack.
The platform released a detailed post-mortem report on Wednesday, revealing that unauthorized parties accessed off-chain infrastructure and injected manipulated BTC-USD price data into the system.
Off-Chain Infrastructure Identified as Attack Vector
Ostium’s investigation revealed that the falsified price information enabled attackers to register fabricated trading gains. The extracted capital originated from the publicly accessible OLP vault, which serves as the liquidity backbone for platform trading operations.
Attackers leveraged existing forwarder pathways that the protocol had already authenticated. An initial test transaction involving 100 USDC produced approximately 897.8 USDC in counterfeit gains before the main exploitation commenced.
The primary withdrawal moved 11.9 million USDC into an attacker-controlled wallet. Subsequently, six additional trading sequences were executed using identical methodology.
Total damages amounted to 23.75 million USDC. The platform’s automated surveillance infrastructure identified the suspicious activity and halted additional withdrawals, preventing further capital loss from the vault.
Protocol Smart Contracts and User Assets Unaffected
Ostium’s technical review confirmed the absence of vulnerabilities within its smart contract architecture. The investigation also verified that protocol multisig wallets remained under proper governance control throughout the incident.
Trader collateral remained completely insulated from the security incident. All user margin stayed secured within the protocol’s trading contract infrastructure, with losses confined exclusively to the OLP liquidity vault holdings.
The exchange transitioned operations to a newly configured production environment featuring enhanced security protocols. Trading functionality resumed on July 23 following successful migration completion.
Management is developing a compensation framework for impacted liquidity providers. Ostium indicated that comprehensive details regarding the recovery initiative will be disclosed upon finalization.





