Hackers steal $23.7 million in crypto from Ostium in off-chain attack

A massive cryptocurrency heist has unfolded on the decentralized trading platform Ostium, with attackers making off with a staggering $23.7 million. The incident, which occurred last week, saw the perpetrators exploit vulnerabilities in off-chain infrastructure used to feed prices into the protocol. Ostium has confirmed that an attacker submitted fake price reports and rapidly opened and closed large positions to generate artificial profits, ultimately stealing from the platform’s liquidity provider vault.

The affected trading platform, Ostium, is built on the Arbitrum blockchain scaling solution, allowing users to speculate on the prices of traditional and crypto assets directly from a cryptocurrency wallet. Prices are supplied to the protocol via external data feeds, while trades are settled in USDC, a stablecoin designed to maintain a 1:1 peg to the US dollar. Ostium first notified its community about the incident on July 16, when it stated that trading had been paused due to a security incident.

According to blockchain security firm PeckShieldAlert, the attackers exploited vulnerabilities in off-chain infrastructure to manipulate prices and steal from the liquidity provider’s vault. The stolen funds were then swapped for Ethereum and deposited into TornadoCash, a cryptocurrency mixer designed to obscure the origin of cryptocurrencies. Ostium has clarified that trading amounts for leveraged positions are stored in a separate smart contract and were not impacted by this incident.

The security breach raises concerns about the vulnerability of decentralized trading platforms to off-chain attacks. Off-chain infrastructure is often used to feed prices into protocols, but it can also be exploited by attackers if not properly secured. Ostium’s incident highlights the importance of robust security measures in preventing such attacks and protecting user assets.

As trading on Ostium remains paused, the platform has promised to provide at least 24 hours’ notice before operations resume. The company has also pledged to conduct a post-mortem analysis with technical details in the coming days. This incident serves as a reminder that even decentralized platforms are not immune to security risks and that robust security measures must be in place to protect user assets.

In light of this incident, users of decentralized trading platforms should remain vigilant and ensure that their platforms have robust security measures in place to prevent off-chain attacks. It’s also essential for traders to understand the potential risks associated with decentralized trading and to take steps to mitigate those risks. By doing so, we can minimize the impact of such incidents and protect our digital assets.


Source: Bleeping Computer — 2026-07-20