Ostium said an attacker stole $23.75 million from its liquidity provider vault after compromising the off-chain infrastructure that supplied price data to the Arbitrum-based decentralized trading platform. According to the company, the attacker submitted manipulated price reports that appeared legitimate, then rapidly opened and closed large positions to generate artificial profits. Ostium said trader collateral was not affected because it is held in a separate contract, and existing positions remain recorded but frozen while trading is paused.
The platform said it halted trading within about an hour of the first exploit transaction, notified relevant authorities, and plans to publish a post-mortem before restarting services. Blockchain security reporting indicated the stolen USDC was swapped for 12,080 ETH, with 10,540 ETH later deposited into Tornado Cash, complicating efforts to trace and recover the funds.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A November 2025 Zellic audit warned that a compromised forwarder could create the kind of price-delivery risk later used in the Ostium exploit. The report says Ostium fixed only the specific example and did not expand its review or bug bounty coverage to the broader risk class.
Ostium said it will reopen trading on July 23 after the exploit-related pause. The protocol said positions and pending orders will carry over and be marked to the live market price at reopening, while new OLP liquidity-provider deposits will remain paused during recovery.
Blockchain security reporting indicated the stolen USDC was converted to Ethereum, with 12,080 ETH obtained and 10,540 ETH later deposited into Tornado Cash.
Ostium said it paused trading within 60 minutes of the first exploit transaction and notified relevant authorities. The platform also stated that trader collateral was unaffected because it is held in separate contracts, while existing positions were frozen pending a restart notice and post-mortem.
Ostium disclosed that an attacker compromised the off-chain infrastructure supplying price data, submitted fraudulent price reports that appeared legitimate, and used them to open and close large positions for artificial profits, stealing $23.75 million from the liquidity provider vault.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcexakep.ru
Open sourcecysecurity.news
Open sourcethedefiant.io
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.