Ostium Resumes Trading in Stages After $24M Oracle Hack

Ostium Resumes Trading in Stages After $24M Oracle Hack

On July 23, Ostium, a decentralized perpetual trading platform on Arbitrum specializing in real-world assets (RWAs), announced the reopening of trading at 10:00 AM ET. The reopening is happening in stages after a major security incident on July 15, when about $23.75 million in USDC was stolen from its liquidity provider vault.

In the official announcement shared on X, the Ostium team revealed that “At reopen, protective and reduce-only actions come first: closing positions, topping up collateral, updating or cancelling orders, and automated take-profits, stop-losses, and liquidations. Opening new positions follows shortly after, once pending orders have cleared. A further update will confirm when full trading is live.”

“The system executes only on live prices. No position can be filled or liquidated at a price from before the pause,” stated in the post.

According to the official statement, existing positions and pending orders are the same. When trading resumed, they were priced at the market rate at that exact moment. Ostium clarified that liquidation or triggered orders will only happen based on prices at reopen, not any price changes during the pause.

What Went Wrong On Ostium?

The hack targeted Ostium’s off-chain price feed system. In the detailed report, the Ostium team revealed that the attacker submitted fake price reports with future dates through the PriceUpKeep forwarder, making it look like they were making highly profitable trades. They opened and closed large positions quickly, draining money from the OLP vault.

In the security incident, hackers have managed to steal around $23.75 million worth of USDC, with Ostium confirming the exact amount at 23,752,746 USDC. The protocol froze trading and contracts within about 60 minutes of the first suspicious transaction. Also, Trader funds stayed safe in separate contracts.

Ostium is working with cybersecurity firms like Mandiant, zeroShadow, Collisionless, and SEAL 911, as well as law enforcement. They are also coordinating with exchanges, bridges, and stablecoin issuers to track and possibly freeze the stolen funds. The attacker reportedly moved the stolen funds by using a popular cryptocurrency mixer like Tornado Cash.

Based on our ongoing investigation, the attacker compromised off-chain infrastructure related to the system that feeds prices into the protocol. The attacker then submitted illegitimate price reports that were manipulated to appear as valid, opening and instantly closing a series of large positions to extract an artificial profit from the vault. By design, trader collateral sits in a separate, isolated contract and is not affected, with all positions remaining open,” stated in the official post.

Ostium is known for leveraged perpetual trading with up to 200x leverage on selected pairs across 75 assets, including stocks, ETFs, commodities, indices, forex, and crypto. The platform is focusing on self-custody, instant USDC settlement on Arbitrum, and deep liquidity through off-chain hedging partners like Jump. Before the hack, it had processed over $50 billion in trading volume. Apart from this, Ostium has also raised $27.8 million in a Series A funding round.

The hack on the platform has once again exposed vulnerabilities in oracle and off-chain automated systems, which have been a recurring issue in DeFi lately. It is true that Ostium’s hybrid model combines on-chain settlement with off-chain price feeds. This mechanism is important to make RWA trading efficient; however, it also introduced some vulnerabilities on the platform.

While the crypto sector is growing rapidly, DeFi platforms are constantly facing threats from hackers.

Earlier this month, SecondFi rolled out a detailed Hardware Wallet Migration Guide following the revelation of a wallet generation software vulnerability that was exploited in late June. 

In the last 6 months, DeFi has been hit hard by hacks in the second half of 2026, with hundreds of millions lost across dozens of attacks. Oracle and cross-chain bridge exploits were a major factor. Summer.fi was drained of $6 million in early July, leading to its shutdown. Bonzo Lend lost roughly $9 million after an oracle flaw let users borrow far more than they should have.