The off-chain attack exposed vulnerabilities in external price infrastructure, forcing Ostium to suspend trading while it investigates the $23.75 million theft.
Hackers stole $23.75 million from Ostium’s liquidity provider vault on July 15 after compromising the Arbitrum-based trading platform’s off-chain price infrastructure, forcing an immediate halt to all trading.
Ostium disclosed that the incident occurred after attackers compromised the off-chain attack vector involving external infrastructure used to deliver price data to the protocol. The exploit, first detected on July 16, targeted the platform’s price reporting system rather than its on-chain smart contracts, allowing the attacker to manipulate market prices and generate fraudulent profits.
While liquidity providers suffered losses, Ostium said trader collateral remained secure and existing trading positions were unaffected.
The off-chain attack targeted the infrastructure responsible for supplying market prices to Ostium, a decentralized trading platform built on the Arbitrum blockchain that allows users to trade both cryptocurrency and traditional financial assets directly from their digital wallets.
According to Ostium’s latest incident update, the attacker successfully submitted illegitimate price reports disguised as authentic data. By exploiting manipulated prices, the attacker rapidly opened and closed large leveraged positions, extracting approximately $23.75 million from the platform’s liquidity provider vault.
“The attacker submitted illegitimate price reports disguised as valid ones, then rapidly opened and closed large positions to generate artificial profits,” — Ostium, in its official incident update.
The company emphasized that the off-chain attack did not compromise the protocol’s core smart contracts. Instead, it exploited the external systems responsible for feeding pricing information into the decentralized trading platform.
Ostium initially informed users of a security incident on July 16, announcing that trading had been paused while the platform investigated the breach. Authorities were also notified, and the company confirmed that efforts to trace the stolen assets had begun.
Trader funds remain safe despite off-chain attack
Despite the scale of the off-chain attack, Ostium stressed that customer collateral remained protected because it is stored separately from the affected liquidity provider vault.
The company explained that leveraged trading positions are maintained within a different smart contract that was never compromised during the incident. As a result, users did not lose the collateral backing their trades.
“Trader collateral was held in a separate contract and was not affected, while existing positions remain open,” — Ostium, official platform update.
Although long and short positions remain recorded on-chain, they are effectively frozen because all trading activity was suspended within approximately 60 minutes of the first exploit transaction.
Ostium said trading will remain paused until the affected infrastructure is secured and users will receive at least 24 hours’ notice before the platform resumes operations.
When trading restarts, all positions will be marked to the reopening market price.
The off-chain attack highlights how decentralized finance protocols can remain vulnerable even when their smart contracts themselves are secure, particularly if they rely on external infrastructure such as price oracles and data feeds.
Stolen funds traced after off-chain attack
Blockchain security firm PeckShield tracked the movement of the stolen cryptocurrency shortly after the off-chain attack.
According to the firm’s analysis, the attacker swapped the stolen USDC for approximately 12,080 Ether before moving 10,540 Ether into Tornado Cash, a cryptocurrency mixing service commonly used to obscure blockchain transaction trails.
Money trace from the incident Source: PeckShieldAlert
“The exploiter swapped the stolen USDC for 12,080 Ethereum and then deposited 10,540 Ethereum to TornadoCash,” — PeckShieldAlert, blockchain security firm.
The movement of the assets through Tornado Cash is expected to complicate recovery efforts, although Ostium said it continues to monitor the stolen funds while cooperating with relevant authorities.
The company is also working to secure the compromised infrastructure and determine how liquidity providers will be supported following the breach.
Ostium prepares post-mortem after off-chain attack
Five days after the off-chain attack, trading on Ostium remains suspended as engineers continue their investigation into the exploit.
The company has pledged to publish a detailed post-mortem report outlining the technical root cause of the breach and the security measures that will be implemented before normal operations resume.
The off-chain attack serves as another reminder that decentralized finance platforms depend not only on secure smart contracts but also on the integrity of the external systems that supply critical market data. While blockchain technology offers transparency and immutability, compromised off-chain infrastructure can still expose protocols to significant financial losses.
For liquidity providers, the incident underscores the operational risks associated with decentralized trading ecosystems that rely on external price feeds.
For users, Ostium’s confirmation that customer collateral remained untouched may offer reassurance, but the attack is likely to renew industry discussions around strengthening oracle security, improving infrastructure monitoring, and reducing dependence on centralized components within decentralized finance.
Moses Edozie is a writer and storyteller with a deep interest in cryptocurrency, blockchain innovation, and Web3 culture. Passionate about DeFi, NFTs, and the societal impact of decentralized systems, he creates clear, engaging narratives that connect complex technologies to everyday life.