Future-dated oracle reports drained up to $24M from Ostium

Future-dated authorized oracle reports caused Ostium’s public liquidity vault to pay out, producing estimated losses up to $24 million during a five-minute incident on July 15.

Ostium, an on-chain perpetuals trading platform, experienced a five-minute incident on July 15 when future-dated authorized oracle reports were accepted and triggered payouts from its public liquidity vault. The activity ran from 14:18 to 14:23 UTC.

The team detected the anomaly within minutes and halted trading within an hour, a timeline confirmed by co-founder Kaledora Kiernan-Linn. Ostium has opened an investigation, is working with law enforcement, engaged SEAL 911 and external security specialists, and has not published final loss accounting or a root-cause postmortem.

Technical tracing by several security firms found that authorized reports with future timestamps or otherwise manipulated data produced artificial trading profits that were settled from the Ostium Liquidity Provider (OLP) vault. Early estimates of the payouts varied as analysis progressed: one firm traced roughly $18 million in payouts, another estimated about $23.7 million, and later analysis put the total near $24 million. A separate trace followed a single USDC vault outflow of 11,862,444.782 USDC, about $11.86 million.

One analysis reported that the USDC proceeds were swapped into roughly 12,080 ETH, and that about 10,540 ETH was later sent to a privacy-mixing service. Those technical findings remain subject to confirmation in Ostium’s formal postmortem.

Publicly linked verifier code in Ostium’s documentation recovers an ECDSA signer and checks whether that signer is authorized. The verifier function shown does not enforce a price-plausibility check or a strict timestamp bound, and the available code does not identify which implementation was active during the incident. Any replay protection, timestamp checks, price-deviation limits or multi-source safeguards would need to run elsewhere in the execution flow.

The incident differs from a recent case where a verifier accepted a proof lacking a valid signature. In Ostium’s case, authentication checks reportedly succeeded while the signed data was unsafe. Investigators have not yet determined whether a signer key was compromised, an authorized operator acted maliciously, or another privileged path was abused.

Ostium has indicated that remediation and the postmortem will address signer isolation, stricter timestamp bounds, independent price plausibility checks, payout rate limits and on-chain circuit breakers to limit rapid vault outflows. The protocol has not released a detailed technical report or final loss figures as work continues.

Articles by this author