Loading market data...

Ostium Exploited for $11.86M After Attacker Feeds Fake Bitcoin Price on Arbitrum

Ostium Exploited for $11.86M After Attacker Feeds Fake Bitcoin Price on Arbitrum

On July 15 at 14:18 UTC, an attacker exploited Ostium's trading contracts on Arbitrum, draining roughly $11.86 million in USDC by feeding a fake Bitcoin price of $5,000 while the real price was around $60,000. The exploit targeted the platform's pull-based oracle system, raising fresh questions about the security of decentralized price feeds.

How the exploit worked

The attacker opened a position with a tiny deposit minutes before the exploit, then executed a batch of 20 calls alternating between the Trading contract and a price upkeep contract named OstiumPrivatePriceUpKeep. That contract delivers signed prices from Ostium's oracle system, which uses Stork Network for real-world assets and Chainlink Data Streams for crypto. By submitting a fake Bitcoin price, the attacker created a discrepancy that let them profit from the difference.

Ostium's backing and scale

Ostium is a decentralized perpetuals exchange on Arbitrum focused on real-world assets — stocks, commodities, indices, currencies — as well as crypto pairs. It's backed by General Catalyst and Jump Crypto. The project raised $3.5 million in a seed round in 2023 and a $20 million Series A in December 2025, for a total of roughly $27.8 million. As of July 15, its total value locked stood near $63 million, and it had advertised over $25 billion in cumulative trading volume.

Similarities to the Resolv hack

The exploit bears resemblance to the Resolv USR stablecoin hack in March 2026, where a single privileged role could mint without on-chain limits. In Ostium's case, the exact authorization failure that allowed the fake price to be accepted hasn't been determined yet. The reconciled total loss is also provisional — the on-chain transactions are confirmed, but the final figure may change as investigators dig deeper.

What comes next

Ostium has not released a post-mortem or confirmed whether any funds can be recovered. The team is likely working with security firms and law enforcement, but no public statement has been made as of press time. The unresolved question: how did a single price feed get through without proper validation?