Illustration of a hacker manipulating oracle feeds leading to 18 million USDC loss on Ostium exchange.
Illustration of a hacker manipulating oracle feeds leading to 18 million USDC loss on Ostium exchange.
Gambar dihasilkan oleh AI

Ostium loses 18 million dollars in oracle attack

Gambar dihasilkan oleh AI

Ostium, a decentralized perpetuals exchange on Arbitrum, lost approximately 18 million USDC after an attacker manipulated its price feed system.

An attacker exploited Ostium's PriceUpKeep forwarder, a component of its automated price-reporting infrastructure, to submit oracle reports with manipulated future timestamps. The falsified data created the appearance of profitable trades and triggered an 18 million USDC payout from the protocol's liquidity vault.

Blockchain security firm Blockaid detected the incident, which occurred on the Arbitrum network. Ostium paused trading after the exploit was reported.

The attack follows a similar 6 million dollar drain from Summer.fi last week. Ostium had raised 27.8 million dollars in funding and processed over 50 billion dollars in trading volume prior to the incident.

Apa yang dikatakan orang

Users discussed the oracle manipulation exploit on Ostium, noting it as a design flaw rather than a code bug. Sentiments ranged from sadness over eroded trust in crypto to skepticism about single-point failures in oracles. Some highlighted ongoing investigations and fund tracing, while others suggested learning from past incidents.

Artikel Terkait

Illustration of cryptocurrency bridges being hacked, showing digital chains breaking and money draining away.
Gambar dihasilkan oleh AI

Crypto bridges lose over $35 million in attacks

Dilaporkan oleh AI Gambar dihasilkan oleh AI

Multiple cross-chain protocols were drained of more than $35 million in a series of attacks spanning six hours. The incidents targeted bridges and staking contracts on Arbitrum, Ethereum and Bitcoin scaling networks.

Hackers stole roughly $3.1 million in PUSD tokens from 11 user wallets on the prediction platform. The theft followed a phishing attack that exploited a compromised third-party vendor.

Dilaporkan oleh AI

AFX and Verus suffered combined losses of $31.69 million in separate incidents on the Ethereum network. A third protocol, B², halted staking after unauthorized access to its upgrade authority.

A federal case is unfolding over $71 million in frozen cryptocurrency following the Kelp DAO exploit, as Aave seeks to release the funds for DeFi recovery. Victims of decades-old North Korean terrorist acts have filed a restraining notice against Arbitrum DAO, claiming the 30,765 ETH as DPRK-linked property. The dispute pits recent hack victims against long-standing terrorism judgment holders.

Dilaporkan oleh AI

Thorchain confirmed a suspected multichain exploit on May 15 that drained about $10 million from users across several networks. The protocol activated emergency halts and has now launched a recovery portal for affected wallets.

LayerZero has acknowledged it made a mistake by allowing its own verifier network to secure high-value assets in a vulnerable setup. The admission comes weeks after a $292 million hack on Kelp DAO that the company had initially blamed on the developer. The firm says its core protocol remained unaffected.

Dilaporkan oleh AI

Humanity Protocol said hackers stole more than $36 million in H tokens by compromising an employee's laptop that held multiple bridge admin keys. The decentralized identity project has halted bridge activity and is working with law enforcement.

 

 

 

Situs web ini menggunakan cookie

Kami menggunakan cookie untuk analisis guna meningkatkan situs kami. Baca kebijakan privasi kami untuk informasi lebih lanjut.
Tolak