Bullish

Ostium Hack Drains 23.75M USDC via Off-Chain Oracle Permission Theft

2026-07-30 08:46:47

Attacker exploited off-chain oracle permissions to forge BTC prices, executing atomic arbitrage to drain $23.75M USDC in 5 minutes before circuit breakers activated.

Woofun AI reports that the Ostium protocol suffered a $23.75 million USDC loss due to compromised off-chain price reporting permissions, rather than smart contract flaws. The attacker utilized legitimate forwarding paths to submit falsified BTC prices of $5,000 and $60,000, initiating an atomic arbitrage cycle with an initial $100 USDC position. Over eight transactions within five minutes, the attacker drained the OLP treasury until the circuit breaker mechanism engaged. The breach highlights a critical lack of multi-party approval in off-chain infrastructure, creating a single point of failure. Stolen funds were converted to ETH and laundered through Tornado Cash, with tracking efforts currently underway.

WOOFUN AI

Impact Assessment · Quick Read

This incident underscores the systemic risk of centralized off-chain oracle permissions, which can bypass on-chain security measures like multi-signatures. The rapid execution via atomic transactions suggests sophisticated pre-planning, potentially impacting trust in similar hybrid oracle architectures. While funds are being mixed, the exposure of such vulnerabilities may prompt protocols to audit their off-chain access controls more rigorously.
Generated by WOOFUN AI · For reference only, not investment advice

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions