Incident case file
Sign in to watchOstium — Oracle Signer Key Compromise / PriceUpKeep Forwarder Exploit
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: Attacker EOA: 0x321df194646029e7a6193ea05573d4b9c398bfd9 (seeded by 1 ETH from ChangeNow + 1 ETH from Bybit prior to the attack — not Tornado Cash on the funding side).
Timeline: July 15, 2026, 14:18:48 UTC (Arbitrum block 484137113): attacker executes primary exploit tx 0x359f8c05... — a single atomic executeBatch bundling 20 open/close trade calls on the BTC/USD pair (pairIndex 0). Using a compromised oracle signer key + a registered PriceUpKeep forwarder, the attacker submits properly-signed future-dated authorized oracle reports. One BTC/USD position opens at a fabricated delivered price of $5,000 and closes at ~$60,000; the loop compounds ~10-20 cycles with margin escalation from ~$1K → $80K → $700K per round, up to 900% profit per round. Ostium's verifier controls signer identity, not price accuracy. The contracts execute exactly as designed on false but properly-signed data. Blockaid detects and posts the alert quickly. Blockaid quote (@blockaid_, July 15): 'An attacker used a registered PriceUpKeep forwarder and future-dated authorized oracle reports to create artificial trade profit, triggering a ~$18M USDC payout from the vault.' Ostium tweets: 'We are aware of the issue with the OLP vault. We have paused all trading. The team is investigating.' (initial post later temporarily removed, then reaffirmed July 16). Post-exploit: USDC swapped to ETH via Kyber Network, then ~10,540 ETH routed into Tornado Cash — recovery highly unlikely. July 16: CoinDesk, TechTimes, Galaxy Research coverage. Investigation continues with Blockaid, PeckShield, SEAL 911. No compensation plan announced by end of week. Vector class: same family as KiloEx (April 2025) and Summer.fi (July 6, 2026). The Ostium bug bounty explicitly excluded keepers as 'assumed to be trusted' — not a smart contract flaw, a signer/key management failure outside the audited code perimeter.
Sources and coverage
- Articlexcancel.comhttps://xcancel.com/blockaid_
- Articlecoindesk.comhttps://www.coindesk.com
- Articledecrypt.cohttps://decrypt.co
- Articlethedefiant.iohttps://thedefiant.io
- Articledefiprime.comhttps://defiprime.com
- Articlecryptoslate.comhttps://cryptoslate.com
- Articletronweekly.comhttps://tronweekly.com
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/07/15/ostium-pauses-trading-after-alleged-18m-arbitrum-vault-exploit/
- Articlecrypto.newshttps://crypto.news/blockaid-uncovers-18m-exploit-that-forces-ostium-halt/
- Articlearbiscan.iohttps://arbiscan.io/tx/0x359f8c05b86a4409d60cfba02084334313fd94b19f74a294fb7fc4ea7d4870e0
- Articlearbiscan.iohttps://arbiscan.io/address/0x321df194646029e7a6193ea05573d4b9c398bfd9
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)