Ostium loses $23.75 million after attackers feed the platform fake prices

The decentralised trading platform paused all activity within an hour, but not before a manipulated price feed drained its liquidity vault.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal news-editorial image of an empty modern bank-style vault door swung open, cold blue server-room lighting spilling out, faint h
Share

Key points

  • Ostium, a decentralised trading platform, lost $23.75 million from its liquidity vault after an attack disclosed on July 16, 2025.
  • The attackers did not break the trading contracts, they fed the platform false prices from outside and cashed in on the fake moves.
  • Ordinary traders' deposits were held in a separate contract and were not stolen, though their positions are frozen while trading stays paused.
  • Blockchain trackers at PeckShield say the thief swapped the stolen funds into 12,080 Ethereum and pushed 10,540 of those coins through Tornado Cash, a service that hides where crypto came from.
  • Ostium halted all trading within 60 minutes of the first bad transaction and has promised a full technical write-up.

Ostium, a trading platform that lets people bet on the price of stocks, gold, oil and crypto using a cryptocurrency wallet, has confirmed attackers walked off with $23.75 million last week.

The money came out of what Ostium calls its liquidity provider vault. That is a shared pool of funds, deposited by users hoping to earn a yield, which the platform uses to pay out winning trades.

The attackers never picked the lock on the vault itself. They picked the lock on the thing telling the vault what prices to use.

How did the hackers actually pull this off?

They lied to the platform about prices, and the platform believed them.

Ostium runs on Arbitrum, a network built on top of Ethereum to make crypto transactions cheaper and faster. Trades on Ostium are settled in USDC, a digital dollar meant to hold a steady value of one US dollar per coin.

To know what the price of, say, gold is at any moment, the platform pulls data from an outside price feed. That feed is called "off-chain infrastructure", meaning it runs on normal servers rather than on the blockchain itself.

That off-chain piece is what got broken into.

The attackers submitted fake price reports dressed up to look real. Then they opened large positions, waited for the fake price move to register as "profit", and closed them. Rinse and repeat until the vault was empty.

In practice, this is the classic oracle manipulation failure. The smart contract code did what it was told. It was told nonsense.

What happened to the money?

Blockchain security firm PeckShield traced the stolen USDC as it was swapped for 12,080 Ethereum. Of that, 10,540 Ethereum was then pushed into Tornado Cash, a mixing service that scrambles the trail between sender and receiver.

Once funds go through a mixer, recovery becomes very difficult. Not impossible, but the working assumption inside the industry is that this money is gone.

Did ordinary traders lose their deposits?

No, according to Ostium.

The collateral posted by regular users, the money they put up to open a trade, sits in a separate smart contract. That contract was not touched. Open long and short positions were not force-closed or liquidated.

Those positions are effectively frozen. Trading was paused across the whole platform within 60 minutes of the first bad transaction, first reported by BleepingComputer, and it is still paused five days on.

Ostium says it will give at least 24 hours' notice before trading reopens. When it does, positions will be marked at the reopening price, so users will see gains or losses based on where the market has moved in the meantime.

What should users do now?

If you have funds or open trades on Ostium, watch the platform's official channels for the promised post-mortem and the notice before trading resumes. Do not click links from strangers offering "recovery services" or "refund forms". Scammers always turn up in the replies after a crypto incident.

One thing the post-mortem will almost certainly say: the price feed did not have enough sanity checks. Manipulated oracles have drained decentralised finance platforms for years, and the failure mode here is depressingly familiar.

Operational takeaway: if your protocol trusts a single off-chain input, that input is your vault key.

© 2026 Threat Vectr