Ostium's post-mortem on the July 15 exploit confirms that attackers drained 23,752,746 USDC, about $23.75 million, from its public OLP liquidity vault. The breach did not exploit a flaw in the audited smart contracts. Instead, the compromise hit the off-chain system that signs the protocol's price feeds, letting attackers submit illegitimate price reports during a window of roughly five minutes (14:18 to 14:24 UTC). Trader collateral was not touched. The exchange paused trading within an hour of the first malicious transaction and reopened on July 23 after migrating to a new production environment with multi-party approvals and additional security controls. The episode is a reminder that the security surface of a DeFi protocol includes more than its on-chain code: off-chain components such as price signers and oracle permissions can bypass the guarantees of an audited contract if their access controls fail.
The Crypto Times