Ostium loses $18 million to oracle manipulation attack via PriceUpKeep exploit
An attacker drained approximately $18 million in USDC from Ostium's vault on Arbitrum by exploiting the protocol's PriceUpKeep oracle component. The attacker submitted future-dated price reports to manufacture fake profitable trades. The exploit was detected by security firm Blockaid and marks another in an escalating series of keeper-system attacks on DeFi protocols.
A hacker drained approximately $18 million in USDC from Ostium's liquidity vault on Arbitrum by exploiting the protocol's PriceUpKeep oracle component, according to CoinDesk. The attacker, identified by blockchain security firm Blockaid, leveraged a registered PriceUpKeep forwarder, a component of Ostium's automated infrastructure, to submit oracle price reports with future-dated timestamps. Those manipulated oracle reports created the appearance of profitable trades, which triggered the $18 million USDC payout from the vault.
Ostium is a decentralized perpetuals exchange on Arbitrum that allows users to trade real-world assets including commodities, forex, and equity indices with up to 200x leverage, settling in USDC, per CoinDesk's reporting. Before the exploit, Ostium had processed over $50 billion in cumulative trading volume. The protocol uses a custom price-feed system to track real-world asset prices, with Gelato, a third-party automation network, responsible for pushing those prices onchain. The PriceUpKeep smart contract acts as the trigger that writes the latest price data to the blockchain whenever a trade needs to be executed.
The attack pattern fits a widening category of keeper-system exploits targeting DeFi automation infrastructure. Last week, $6 million was drained from Summer.fi in a similar keeper-system attack, per CoinDesk's reporting. Both incidents exploit the trust model that protocols extend to registered keepers and automation components. Rather than targeting the core trading or lending logic, attackers have begun escalating privileges within the automation layer itself, abusing the position to report false prices and trigger unauthorized payouts.
Ostium had raised $27.8 million in total funding, including a $24 million Series A co-led by General Catalyst and Jump Crypto in late 2025, according to CoinDesk. The exploit was significant enough to prompt Blockaid detection, suggesting either the transaction volume or the payout size triggered security monitoring.
The bear case is structural. Keeper-system exploits are not Ostium-specific but point to a systemic architectural vulnerability across DeFi: protocols that rely on registered external keepers and automation networks create privilege escalation points that are difficult to defend. An attacker who gains access to or compromises a registered keeper role can submit false data at will. Defending this attack surface requires either eliminating the keeper role entirely, moving price feeds to truly decentralized oracle networks (which introduces other latency and cost trade-offs), or implementing multi-signature or threshold governance on price submissions.
Attacker exploited Ostium's PriceUpKeep forwarder to submit future-dated oracle price reports that created the appearance of profitable trades, triggering an $18 million USDC payout from Ostium's vault on Arbitrum, detected by Blockaid.
Watch for Ostium's recovery plan and whether it compensates affected users. More broadly, monitor whether other protocols using similar Gelato or keeper-based automation models announce defensive changes to their oracle or price-feed permission models. If exploits of this type continue to cluster around automation networks, it will pressure DeFi protocols to abandon keeper-based price feeds in favor of fully decentralized or on-chain oracle alternatives.
And that's the way it is.
Not financial advice. Crypto Cronkite reports events and explains what they may mean. It never tells you to buy or sell anything. Do your own research.