๐Ÿ“… Saturday, 19 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Bursa DeFi Ostium Dikuras $18 Juta - Peretas Justru Pakai Sistem Harga Milik Ostium Sendiri

DeFi Exchange Ostium Drained of $18M - Hacker Exploited Platform’s Own Price System

It was neither a cross-chain bridge nor a leaked private key. The hacker who drained approximately $18 million in USDC from Ostium this time used a far more cunning weapon: Ostium’s own price infrastructure. Blockchain security firm Blockaid detected the attack, with the modus operandi sending chills across the DeFi industry.

Ostium is a decentralized perpetual exchange on the Arbitrum network that enables the trading of real-world assets - commodities, forex, and stock indices - with up to 200x leverage. In this exploit, the liquidity vault serving as the platform’s backbone was breached.

How a Fake Clock Unlocked an $18 Million Vault

The key to the attack lay in a component called PriceUpKeep, a registered forwarder that is part of Ostium’s automated infrastructure. The attacker exploited this forwarder to submit oracle price reports with future-dated timestamps.

The forged oracle reports created the illusion of profitable trades. That illusion subsequently triggered the withdrawal of around $18 million in USDC from Ostium’s vault - as if the system were paying out profits that never actually existed.

Ostium itself uses a custom price-feed system. A third-party automation network named Gelato was tasked with pushing price data on-chain, while the PriceUpKeep smart contract acted as a trigger to record updated price data on the blockchain whenever transactions occurred. It was at this trigger point that the vulnerability was exploited.

An Ongoing Wave of Oracle Attacks

What makes this case even more concerning is that it is not an isolated incident. The attack on Ostium aligns with a broader pattern of oracle and keeper system exploits that have recently struck DeFi. Just last week, Summer.fi lost $6 million through a similar method.

This recurring pattern points to a single shared vulnerability: the mechanism that determines an asset’s price within a protocol. When the pricing system can be deceived, the entire financial logic built upon it collapses.

For DeFi users, the Ostium incident serves as a stark reminder that protocol security does not end at its core contract code. Peripheral components such as keepers and price feeds, often treated merely as technical utilities, have now proven capable of becoming entry points for multi-million-dollar losses. As long as this attack vector continues to claim victims, depositing significant funds into protocols reliant on automated oracles demands extreme caution.

Reported by CoinDesk.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share