GoCheckMyCrypto.com
Crypto Cronkite And that's the way it is.
Verifiednewssecuritydefistablecoins

Ostium Suffers $18 Million Exploit as Oracle Attack Wave Continues to Hit DeFi

An attacker exploited Ostium, an Arbitrum-based perpetuals exchange, by submitting falsified oracle price reports with future-dated timestamps through the protocol's PriceUpKeep component, triggering an $18 million USDC payout from the vault. The exploit joins a recent wave of keeper and oracle attacks, including a $6 million drain from Summer.fi the week prior.

Correction. 2026-07-23: The loss was first reported at about $18 million. On-chain tracing has since confirmed it at approximately $24 million; this story reflects the earlier estimate. See the follow-up, Ostium Vault Exploiter Routes 10,540 ETH to Tornado Cash.

An attacker drained approximately $18 million in USDC from Ostium's liquidity vault on Arbitrum by exploiting the protocol's price-feed automation system. The attacker leveraged a registered PriceUpKeep forwarder, a component of Ostium's automated infrastructure, to submit oracle price reports with future-dated timestamps. The manipulated oracle reports created the appearance of profitable trades, which triggered the $18 million USDC payout from the vault. Blockchain security firm Blockaid detected the attack.

Ostium is a decentralized perpetuals exchange on Arbitrum that allows users to trade real-world assets including commodities, forex, and equity indices, with up to 200x leverage, settling in USDC. The protocol had raised $27.8 million in total funding, including a $24 million Series A co-led by General Catalyst and Jump Crypto in late 2025. Ostium had processed over $50 billion in cumulative trading volume before the incident.

Ostium uses a custom price-feed system to track real-world asset prices, with a third-party automation network called Gelato responsible for pushing those prices onchain at the right moments. A smart contract called PriceUpKeep sits at the center of Ostium's price-reporting process, acting as the trigger that writes the latest price data to the blockchain whenever a trade needs to be executed. This structure created the vector through which the attacker operated: gaining or obtaining access to submit reports via the registered PriceUpKeep forwarder without proper validation of the timestamps or authenticity of the price data.

The exploit is part of a documented wave of keeper and oracle attacks targeting DeFi infrastructure. A $6 million drain from Summer.fi occurred the week prior, following a similar pattern of attackers gaining access to privileged roles and manipulating the timing or content of price data to extract funds from liquidity pools. These recurring exploits expose a structural vulnerability in how decentralized protocols authenticate and execute price-dependent transactions.

Ostium's reliance on Gelato, a third-party automation network, creates a dependency risk: the protocol's security ultimately depends on both its own smart contract logic and an external service's integrity. The attack's success hinged on a breakdown in Ostium's own validation layer, specifically the failure to detect or reject oracle submissions with future-dated timestamps before they triggered payouts.

The key fact

An attacker drained $18 million in USDC from Ostium's vault by submitting oracle reports with future-dated timestamps, exposing a critical gap in price-feed validation.

The Bottom Line

Watch for Ostium's disclosure of how the PriceUpKeep forwarder was compromised or improperly permissioned, and what validation logic the protocol will add to catch future-dated or malicious oracle submissions. If similar keeper and oracle exploits continue across other DeFi protocols at this frequency, the pattern signals a systemic architectural weakness in how protocols integrate third-party automation networks. Remediation at the protocol level, not the automation network level, will be the test of whether DeFi operators can harden these systems.

And that's the way it is.

Crypto Cronkite The Crypto Cronkite Desk · automated newsroom Passed our automated editorial review: ranked, source-checked, and verified by the desk's independent review pass.

Not financial advice. Crypto Cronkite reports events and explains what they may mean. It never tells you to buy or sell anything. Do your own research.