Ostium, a decentralised perpetuals exchange on Arbitrum, suffered a significant loss on 15 July 2026, when an attacker drained approximately $18 million in USDC from its liquidity vault, which held around $63 million in total value locked (TVL), resulting in a loss of nearly 28% of the vault's value, according to on-chain data, with blockchain security firm Blockaid flagging the incident on the same day, affecting investors and the broader crypto market.
Exploiting the Price System
The attacker exploited Ostium's custom price-feed system, which relies on Gelato, a third-party automation network, to post asset prices at set intervals, and a component called the PriceUpKeep forwarder to push oracle updates when trades execute, by submitting reports with future-dated timestamps using a registered PriceUpKeep forwarder, making unprofitable trades appear profitable and triggering the vault payout, with the attacker able to bypass the protocol's verification checks due to a compromised oracle signer key, allowing them to open and close positions in a loop, extracting value without taking real market risk, and impacting the price of USDC and the overall blockchain ecosystem.
Market Impact and Investigation
The incident has significant implications for the crypto market, particularly for investors in Ostium and users of the Arbitrum blockchain, as it highlights the importance of robust security measures and the potential risks associated with decentralised perpetuals exchanges, with the loss of $18 million in USDC likely to affect market sentiment and the price of the coin, as the community awaits further investigation and updates from Ostium and Blockaid on the incident, which may impact the future of the blockchain and crypto industry as a whole, and the use of stablecoins like USDC in decentralised finance (DeFi) applications.
