Ostium protocol exploit
The Ostium protocol exploit occurred on July 15, 2026 Verified Answer #1. While early reports estimated losses at approximately $11.86 million to $18 million, later reconciliations indicated the total loss was between $23.7 million and $23.75 million across multiple transactions Verified Answer #1.
Exploit Mechanism
The incident is characterized as a price-authority or oracle-authorization exploit rather than a standard arithmetic bug Verified Answer #1. The attacker utilized an authorized oracle signer and a registered price-upkeep forwarder to execute the drain Verified Answer #1. The core vulnerability involved Ostium's contracts validating the identity of the signer without sufficiently verifying if the submitted price was sane, fresh, or temporally valid Verified Answer #1.
The exploit is described as a combination of a key or authorization compromise and insufficient on-chain validation of oracle reports Verified Answer #1. By controlling a valid submitted price report during trade opening or closing, the attacker could extract profits from the liquidity buffer without directly hacking the vault Verified Answer #1.
Protocol Architecture
Ostium utilizes a pull-based price report system where prices are delivered on-chain only when required for trade execution Verified Answer #1. The protocol employs different data sources depending on the asset class: Real World Assets (RWAs) use an Ostium/Stork configuration, while cryptocurrency assets utilize Chainlink Data Streams Verified Answer #1. Additionally, Gelato automation infrastructure is used to trigger trade-related actions Verified Answer #1. When a trader realizes a positive profit, the payout is issued from the OLP liquidity buffer or vault Verified Answer #1.