Ostium Suffers $18 Million Exploit as Oracle Attack Wave Continues to Hit DeFi
An attacker exploited Ostium, an Arbitrum-based perpetuals exchange, by submitting falsified oracle price reports with future-dated timestamps through the protocol's PriceUpKeep component, triggering an $18 million USDC payout from the vault. The exploit joins a recent wave of keeper and oracle attacks, including a $6 million drain from Summer.fi the week prior.
An attacker drained approximately $18 million in USDC from Ostium's liquidity vault on Arbitrum by exploiting the protocol's price-feed automation system. The attacker leveraged a registered PriceUpKeep forwarder, a component of Ostium's automated infrastructure, to submit oracle price reports with future-dated timestamps. The manipulated oracle reports created the appearance of profitable trades, which triggered the $18 million USDC payout from the vault. Blockchain security firm Blockaid detected the attack.
Ostium is a decentralized perpetuals exchange on Arbitrum that allows users to trade real-world assets including commodities, forex, and equity indices, with up to 200x leverage, settling in USDC. The protocol had raised $27.8 million in total funding, including a $24 million Series A co-led by General Catalyst and Jump Crypto in late 2025. Ostium had processed over $50 billion in cumulative trading volume before the incident.
Ostium uses a custom price-feed system to track real-world asset prices, with a third-party automation network called Gelato responsible for pushing those prices onchain at the right moments. A smart contract called PriceUpKeep sits at the center of Ostium's price-reporting process, acting as the trigger that writes the latest price data to the blockchain whenever a trade needs to be executed. This structure created the vector through which the attacker operated: gaining or obtaining access to submit reports via the registered PriceUpKeep forwarder without proper validation of the timestamps or authenticity of the price data.
The exploit is part of a documented wave of keeper and oracle attacks targeting DeFi infrastructure. A $6 million drain from Summer.fi occurred the week prior, following a similar pattern of attackers gaining access to privileged roles and manipulating the timing or content of price data to extract funds from liquidity pools. These recurring exploits expose a structural vulnerability in how decentralized protocols authenticate and execute price-dependent transactions.
Ostium's reliance on Gelato, a third-party automation network, creates a dependency risk: the protocol's security ultimately depends on both its own smart contract logic and an external service's integrity. The attack's success hinged on a breakdown in Ostium's own validation layer, specifically the failure to detect or reject oracle submissions with future-dated timestamps before they triggered payouts.
An attacker drained $18 million in USDC from Ostium's vault by submitting oracle reports with future-dated timestamps, exposing a critical gap in price-feed validation.
Watch for Ostium's disclosure of how the PriceUpKeep forwarder was compromised or improperly permissioned, and what validation logic the protocol will add to catch future-dated or malicious oracle submissions. If similar keeper and oracle exploits continue across other DeFi protocols at this frequency, the pattern signals a systemic architectural weakness in how protocols integrate third-party automation networks. Remediation at the protocol level, not the automation network level, will be the test of whether DeFi operators can harden these systems.
And that's the way it is.
Not financial advice. Crypto Cronkite reports events and explains what they may mean. It never tells you to buy or sell anything. Do your own research.