TechFlow Logo
Login/ Sign up
ETH Gas
Gwei
Fear
gas
7x24hNews

Ostium Attack Post-mortem: Off-chain Oracle Permissions Stolen, Forged BTC Price to Arbitrage 23.75 Million USDC

2026.07.30 - 00:45
Share

7x24h News

Ostium Attack Post-mortem: Off-chain Oracle Permissions Stolen, Forged BTC Price to Arbitrage 23.75 Million USDC

According to Ostium's official report, the core of this attack lies in the compromise of the off-chain price reporting system permissions, unrelated to smart contract vulnerabilities. After obtaining off-chain authorization, the attacker utilized the protocol's registered legitimate forwarding paths to submit forged prices ($5,000 and $60,000) to the BTC-USD market, atomically completing an open-close position arbitrage cycle within the same transaction. Starting with 100 USDC and rolling to amplify the scale across 8 transactions, they extracted 23.75 million USDC from the OLP vault within 5 minutes until the vault circuit breaker mechanism was triggered. The root cause lies in the off-chain infrastructure lacking a multi-party approval mechanism equivalent to on-chain multi-signature, creating a single-point permission vulnerability. The stolen funds have been converted to ETH and mixed via Tornado Cash; tracking efforts are still ongoing.

2026.07.30 - 00:45:53

TechFlow reports, on July 30, according to Ostium's official report, the core of this attack lies in the compromise of off-chain price reporting system permissions, unrelated to smart contract vulnerabilities.

After obtaining off-chain authorization, the attacker exploited the protocol's registered legitimate forwarding paths to submit forged prices ($5,000 and $60,000) to the BTC-USD market, atomically completing an open-close position arbitrage cycle within the same transaction, starting with 100 USDC to roll and amplify the scale, across 8 transactions, extracting 23.75 million USDC from the OLP Vault within 5 minutes, until the vault circuit breaker mechanism was triggered.

The root cause lies in the off-chain infrastructure lacking a multi-party approval mechanism equivalent to on-chain multisig, creating a single-point permission vulnerability. The stolen funds have been converted to ETH and mixed through Tornado Cash, and tracking efforts are still underway.

Add to Favorites
Share to Social Media
TechFlow Logo

Navigating Web3 tides with focused insights

Contribute An Articleemail
Media Requestsmsg

Risk Disclosure: This website's content is not investment advice and offers no trading guidance or related services. Per regulations from the PBOC and other authorities, users must be aware of virtual currency risks. Contact us / [email protected] ICP License: 琼ICP备2022009338号