Another DeFi Exploit: Perp DEX Ostium Loses $18 Million in Oracle Attack

by shayaan
Decrypt logo

In short

  • Ostium lost about $18 million USDC on Wednesday due to an oracle exploit.
  • Attackers used a compromised Oracle signing key to submit falsified, forward-dated pricing reports.
  • The exploit cost almost a third of the protocol’s liquidity.

Ostium lost about $18 million on Wednesday after attackers compromised an oracle key and manipulated the decentralized perpetuals exchange’s price feed to generate fake trading profits, according to blockchain security firm Blockaid.

In one after on stable currency USDC – from the Ostium liquidity vault.

“We are aware of the issue with the OLP vault,” Ostium said wrote on X. “We have halted all trading. The team is investigating.”

Built on arbitrage, Ostium offers perpetual futures linked to real-world assets including stocks, commodities, currency markets and indices. It works as a decentralized exchange, or DEXmeaning users largely retain control of their money and do not provide any personally identifiable information. At the time of the attack, the protocol was holding approximately $63 million in total value, meaning the exploit took away almost a third of its liquidity.

The attack comes amid one of the worst years ever for DeFi exploits. DeFior decentralized finance, refers to financial applications that operate natively on blockchain networks, without third-party intermediaries such as banks. In the first five months of 2026, more than $840 million was stolen from DeFi protocols, including $292 million from KelpDAO and $285 million from the Drift Protocol. Hackers also targeted Resolv Labs in June, stealing more than $25 million.

Security experts warn that advances in artificial intelligence are accelerating the discovery of exploits.

See also  Cynthia Lummis Tapped to Lead First-Ever Senate Crypto Subcommittee

“AI is much better at reviewing code than most humans and finding potential vulnerabilities in it,” said Danny Jenkins, CEO and co-founder of ThreatLockertold earlier Declutter. Jenkins said current AI systems already accelerate vulnerability discovery, while newer models like Mythos could significantly expand those capabilities, calling it a looming “major problem.”

“It will only be a matter of time before someone bad gets access to it,” he said.

In May, security researcher Taylor Hornby used Anthropic’s Claude Opus 4.8 to identify a four-year-old counterfeit vulnerability in Zcash, underscoring how groundbreaking AI models are becoming increasingly effective at finding complex software bugs.

Daily debriefing Newsletter

Start every day with today’s top news stories, plus original articles, a podcast, videos and more.

Source link

You may also like

Latest News

Copyright © Sovereign Wealth Signals