Back to news

Hackers steal $18M USDC from Ostium liquidity vault on Arbitrum via oracle manipulation

Unknown attackers stole approximately $18 million in USDC stablecoins from the liquidity vault of the Ostium platform on the Arbitrum blockchain.

Unknown attackers stole approximately $18 million in USDC stablecoins from the liquidity vault of the Ostium platform on the Arbitrum blockchain. The attack was made possible through oracle data manipulation, according to security specialists from Blockaid.

The attackers exploited the registered PriceUpKeep forwarder — an element of Ostium's automated infrastructure. Using it, they sent price reports from the oracle with future dates. The system detected profitable trades and automatically paid out millions in stablecoins from the vault.

Ostium is a decentralized perpetual contract exchange built on Arbitrum. The platform allows trading real-world assets — commodities, currency pairs, and stock indices — with leverage up to 200x, settled in USDC. A third-party automation network, Gelato, is responsible for sending price data, with the PriceUpKeep smart contract playing a key role.

Ostium has raised $27.8 million in funding, including investments from General Catalyst and Jump Crypto. The platform's total trading volume exceeds $50 billion.

This is not an isolated incident. Last week, $6 million was drained from the Summer.fi protocol, and the Bonzo Lend crypto lending protocol on Hedera lost about $9.05 million. The attacks share a common pattern: attackers gain access to privileged roles and manipulate the timing or content of price data to drain liquidity pools.

Stay vigilant. Even major platforms with multi-million-dollar funding are not immune to oracle vulnerabilities.

WARNINGTronUSDTTX7f…3kP9BLOCKEDEthereumUSDC0xA1B2…9F00UNBLOCKEDTronUSDTTA4m…8rQ2BURNEDEthereumUSDC0x7C8D…21E4