Perp DEX Loses $23.75M in Oracle Key Exploit, Resumes Trading July 23


On July 15, 2026, the persistent DEX Ostium was down $23.75 million USDC after a hacker got hold of the private signing key and used it to make fake trades until the repository ran out. Ostium suspended trading less than an hour after the first negative reaction, and after eight days of investigation and persistence, reopened the platform on July 23.

Unlike the smart bullets that once dominated the headlines of DeFi, this attack focused on the devices that assign prices in the protocol – a field where most analytics and payments are not paid to be viewed.

Advertising

xtb-nike-share-free

What happened to Ostium?

The cause was the private oracle signing key rather than Ostium’s Solidity code problem. Security firm Blockaid, which first reported the incident, said the attacker used PriceUpKeep’s subscription fee to send future, legitimate reports. Those reports tricked the system into thinking that several trades were profitable.

From there, the attacker made about 20 open and close trades through the transactions he was sent, repeatedly paying money from Ostium’s main OLP (liquidity providers) room without looking at the real market. The payment logic of the storeroom believed that the fake price was real, so they set up sales that only seemed profitable because the food turned out to be fake.

Why are oracle signing keys so many?

The oracle signing key acts as a password for the tree data. When a system like Ostium implements a perpetual transaction, it relies on the signed currency to decide who is profitable and who is not. Anyone who can control the signing key can tell the protocol any value they want – bypassing the checks that are made to keep the food honest.

That’s what makes this attack group so dangerous. Smart contracts did exactly what they were designed to do; they just followed fraudulent advice from someone they shouldn’t have. It is compatible with 2026 which is very large DeFi the losses only come from human resources and infrastructure rather than buggy code.

How much was lost, and where did the money go?

Ostium confirmed the exact number: 23,752,746 USDC released from the OLP vault. Initial estimates varied — Blockaid put the losses at around $18 million and CertiK at around $22 million — but its protocol accounts settled at around $23.75 million. Galaxy Research tracked eight payments to one wallet, including transfers of approximately $11.86 million, $4.49 million, and $3.59 million.

Worse, the transaction shared funds in OLP’s public reserves, not commercial collateral. Trader’s Edge has been isolated and parked within smart contracts throughout this process. The stolen USDC, however, was converted to approximately 12,084 ETH and was processed through the Tornado Cash mixing service, which greatly reduces the chance of recovery.

Advertising

xtb-nike-share-free

Has the Ostium hack been solved?

A little bit. Trading resumed on July 23 at 10:00 am ET (2:00 pm UTC), but did not close. Here’s where things stand:

Trading was re-opened in stages – risk management services and mitigation orders only returned first, with the remaining products gradually restored to stabilize the system. Open positions are pending orders that were executed instead of closed during the closing period, and each position was recalculated at the market price that was re-opened, so no trader was eliminated due to price changes during the closing period.

Advertising

xtb-nike-share-free

The stolen money was never recovered. Ostium works with cybersecurity firms Mandiant, zeroShadow, and Collisionless, including the SEAL 911 emergency response team and law enforcement, and has been partnering with exchangebridges, and stablecoin providers to explore the currency.

Payments to those involved in liquid funds are still being finalized. Ostium said it will help from its website and partners to repair the affected LPs, but a detailed recovery plan is still pending reopening. So even though the trade is back on track, the returns and LP returns remain open.

Do financial and auditing systems protect a policy like this?

Not by itself. Ostium raised nearly $27.8 million from top sponsors including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute, and GSR, and conducted extensive research. Nothing affected the important management of oracle signers.

In particular, the extent of Ostium’s Immunefi bug bounty scope treated registered keepers – including PriceUpKeep and its distributors – as trustworthy, implicitly placing anything that requires someone to be careless or malicious outside of the program. In other words, the actual attack used was restricted to researchers.

Compare MiCA managed exchanges side by side on our comparison pageCompare MiCA managed exchanges side by side on our comparison page

What does the Ostium hack mean for DeFi and RWA platforms?

It’s yet another reminder that oracle processing is just as important as evaluating smart contracts — more so, as RWA protocols pull equity, stock, forex, and index prices from external sources. Any protocol that relies on a single trusted signing key or a single key provider must ask if it has a single signature problem.

For traders, the takeaways are familiar but worth reiterating: turn off unnecessary contract approvals, be careful with funds parked in DEX warehouses, and look for legitimate trends instead of rumors.

Where can you trade crypto on regulated platforms instead?

Events such as the Ostium hack are a reminder of the trade-offs that come with an unaccounted for or unmanaged environment. In the EU, the MiCA system now implements a similar policy: from July 1, 2026, every platform for sending EU clients requires a Crypto-Asset Service Provider (CASP) license, which covers governance, client security, IT security, and AML requirements. By the end of July 2026, ESMA’s register listed approximately 300 authorized CASPs across the EEA, with one passport authorized in all member states.

If you would like to trade on a legitimate, legitimate platform instead of showing money to an oracle-dependent DEX, it is important to compare the sites with their licenses, fees, and available assets. Our broker and exchange comparison page breaks these down side by side so you can choose the platform that best suits your trading style.

One method is controlled by XTB imagesa publicly listed broker, who has obtained a license to offer crypto trading to EEA clients (through a Cyprus license), along with its authorized trading. You can open an account with XTB Here.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *