← Radar

Incident case file

Sign in to watch

Ostium — Oracle Signer Key Compromise / PriceUpKeep Forwarder Exploit

Incident date July 15, 2026Last updated Jul 18, 2026

1 views

PausedArbitrumOracle manipulation / private key compromiseCluster: OST-ORC-2026-07

Estimated loss

$180M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: Attacker EOA: 0x321df194646029e7a6193ea05573d4b9c398bfd9 (seeded by 1 ETH from ChangeNow + 1 ETH from Bybit prior to the attack — not Tornado Cash on the funding side).

Funds moved to: Primary exploit tx 0x359f8c05b86a4409d60cfba02084334313fd94b19f74a294fb7fc4ea7d4870e0 (Arbitrum block 484137113, 14:18:48 UTC July 15). Single atomic executeBatch bundling 20 open/close trade calls on BTC/USD (pairIndex 0). Confirmed on-chain single-tx extract: 11,861,520 USDC (SlowMist/DeFi Prime figure). Blockaid estimate ~$18M. CertiK estimate ~$22M. Lookonchain/Cyvers estimate ~$23.75M. PeckShield full trace ~$24M (12,084 ETH equivalent). Ostium has not published an official reconciled figur
Attacker EOA 0x321df194646029e7a6193ea05573d4b9c398bfd9. Funding sources: 1 ETH from ChangeNow no-KYC exchange + 1 ETH from Bybit. Ostium Trading contract 0x6D0bA1f9996DBD8885827e1b2e8f6593e7702411. OstiumPrivatePriceUpKeep forwarder (address not spelled verbatim in sources — retrievable via Arbiscan). Compromised oracle signer address: NOT PUBLICLY DISCLOSED. Ostium raised $27.8M in Series A late 2025 (backers: General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute, GSR). >$50B cumulati

Timeline: July 15, 2026, 14:18:48 UTC (Arbitrum block 484137113): attacker executes primary exploit tx 0x359f8c05... — a single atomic executeBatch bundling 20 open/close trade calls on the BTC/USD pair (pairIndex 0). Using a compromised oracle signer key + a registered PriceUpKeep forwarder, the attacker submits properly-signed future-dated authorized oracle reports. One BTC/USD position opens at a fabricated delivered price of $5,000 and closes at ~$60,000; the loop compounds ~10-20 cycles with margin escalation from ~$1K → $80K → $700K per round, up to 900% profit per round. Ostium's verifier controls signer identity, not price accuracy. The contracts execute exactly as designed on false but properly-signed data. Blockaid detects and posts the alert quickly. Blockaid quote (@blockaid_, July 15): 'An attacker used a registered PriceUpKeep forwarder and future-dated authorized oracle reports to create artificial trade profit, triggering a ~$18M USDC payout from the vault.' Ostium tweets: 'We are aware of the issue with the OLP vault. We have paused all trading. The team is investigating.' (initial post later temporarily removed, then reaffirmed July 16). Post-exploit: USDC swapped to ETH via Kyber Network, then ~10,540 ETH routed into Tornado Cash — recovery highly unlikely. July 16: CoinDesk, TechTimes, Galaxy Research coverage. Investigation continues with Blockaid, PeckShield, SEAL 911. No compensation plan announced by end of week. Vector class: same family as KiloEx (April 2025) and Summer.fi (July 6, 2026). The Ostium bug bounty explicitly excluded keepers as 'assumed to be trusted' — not a smart contract flaw, a signer/key management failure outside the audited code perimeter.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)