A $24 million exploit hit Ostium DEX through oracle manipulation, sending the price of Arbitrum's native token down 4%. The attack did not compromise Arbitrum's official bridge, the network confirmed.
How the exploit worked
Attackers manipulated price oracles to drain funds from Ostium, a decentralized exchange built on Arbitrum. The exploit netted roughly $24 million before it was detected. Oracle manipulation is a known vulnerability in DeFi, where attackers feed false data to trigger trades at artificial prices.
ARB token takes a hit
ARB, the governance token of Arbitrum, dropped 4% in the hours following the news. The decline reflects market jitters about the security of applications on the network, even though the core bridge remained untouched.
Bridge security clarified
Arbitrum's native bridge, which moves assets between Ethereum and the layer-2 network, was not hacked. The exploit targeted a third-party DEX, not the bridge itself. The distinction matters for users who rely on the bridge for deposits and withdrawals.
Investigators are still piecing together the full scope of the attack. The incident adds to a growing list of oracle-related exploits in DeFi, highlighting the risks of relying on external data feeds.




