Ostium Excluded Its Oracle From the Bug Bounty. It Cost Them $24 Million
An attacker got hold of one private key and faked a Bitcoin price for five minutes. The gap between fake and real cost Ostium's liquidity providers up to $24 million, and the security hole was explicitly outside the scope of anyone getting paid to find it.

On July 15, 2026, at 14:18 UTC, someone with a stolen private key opened a fake Bitcoin trade on Ostium, an Arbitrum-based perpetuals exchange, at a price of $5,000. Real Bitcoin was trading near $60,000 at the time. Five minutes later, at 14:23 UTC, the position closed. Ostium's liquidity vault was $23.75 million lighter.
Ostium is a decentralized perpetuals exchange built by Kaledora Kiernan-Linn and Marco Antonio Ribeiro, letting traders take leveraged positions on everything from Bitcoin to tokenized real-world assets. The company had raised $27.8 million, including a $20 million Series A co-led by General Catalyst and Jump Crypto, serious backers for a serious platform. Its public OLP vault held the USDC that paid out winning trades.
The attacker never touched Ostium's smart contract code. They compromised the private key belonging to Ostium's price oracle signer, the off-chain system responsible for feeding real-time asset prices into the protocol. With that key, they could digitally sign fake, future-dated price reports and push them through one of Ostium's PriceUpKeep Forwarders as if the reports came from the real oracle.
They used the stolen access to manufacture an artificially low Bitcoin price inside the BTC/USD pair, opened a long position at the fabricated $5,000 print, then closed it the moment the price synced back to reality near $60,000. The gap between fake and real became the attacker's profit, paid straight out of the vault meant to cover winning trades from actual traders.
Researchers who dug into the incident found the exploited component, the PriceUpKeep infrastructure, had been explicitly excluded from the scope of Ostium's own bug bounty program. The one piece of the system someone actually used to steal money was the one piece nobody was being paid to break on purpose.
Ostium's team detected the anomaly within minutes and paused trading contracts inside the hour, according to co-founder Kaledora Kiernan-Linn. The protocol brought in cybersecurity firms Mandiant, zeroShadow, and Collisionless, plus the incident response group SEAL 911 and law enforcement, and began coordinating with exchanges and stablecoin issuers to trace the money. The attacker converted the stolen USDC into roughly 12,084 ETH and routed it through Tornado Cash, the mixing service that has swallowed the trail on nearly every major DeFi hack since 2022.
On-chain investigators reconstructing the attacker's route flagged several deposit addresses tied to exchanges and swap services along the way, plus wallets linked to what looked like an over-the-counter intermediary. None of those addresses had moved funds further at the time they were identified, which gave investigators a narrow window to alert the relevant services before any of it got cashed out for good. Whether that window closes in Ostium's favor is still an open question. Reported loss estimates also drifted during the first days of coverage, from an initial $18 million up to $24 million, before later on-chain analysis settled on $23.75 million as the more precise figure.
Ostium's hack landed in the middle of a brutal stretch for DeFi security. CertiK's Hack3D report put total on-chain losses at $1.3 billion across 344 incidents in the first half of 2026 alone, and two incidents, the $291 million Kelp DAO exploit and the $285 million Drift Protocol breach, accounted for nearly half of that total on their own. Neither of those attacks touched audited code either. Both were key and credential compromises, the same category Ostium just joined.
Trading resumed eight days later, on July 23, with reduce-only orders and phased feature restoration. Deposits into the OLP vault stayed frozen. As of reopening, Ostium had not published a compensation plan for the liquidity providers whose funds were drained, though the team said it intends to contribute from its own balance sheet alongside partners to help make them whole. The stolen funds themselves remain unrecovered. The code did exactly what it was told. The problem was who was doing the telling.
The Aftermath
Ostium reopened for full trading in stages after July 23, but recovery for OLP vault depositors is still unresolved. The stolen funds, converted to ETH and passed through Tornado Cash, have not been recovered. Ostium says it will contribute from its own balance sheet toward making liquidity providers whole, though no formal reimbursement plan had been published as of the reopening. The company continues working with law enforcement and blockchain investigators to trace the attacker's wallet.
COMMENTS