Ostium, a perpetuals exchange built on the Arbitrum network, has lost roughly $18 million after an attacker compromised an oracle signer key and manipulated the price feed. The incident, which the team disclosed on social media, appears to be a direct exploit of the platform's price oracle mechanism rather than a broader smart contract vulnerability.
How the attack worked
The attacker gained control of a key used to sign price data for Ostium's oracle. By feeding false price information, they were able to trigger liquidations or trades at manipulated rates, siphoning funds from the exchange. The team said the exploit targeted the oracle signer specifically, not the underlying Arbitrum chain or Ostium's core contracts.
What Ostium is doing
Ostium has paused all trading and withdrawals while it investigates. The team said it is working with security firms and law enforcement to trace the stolen funds. No timeline has been given for when the platform will resume operations. Users are advised not to interact with the protocol until further notice.
Oracle attacks remain a weak point
Oracle manipulation is a known risk in decentralized finance. Projects that rely on a single or small set of signers for price data are especially vulnerable. Ostium's case is the latest in a string of similar exploits, though the $18 million figure puts it among the larger ones this year. The team has not said whether it will compensate affected users.
The exchange has not announced a plan to relaunch or a timeline for returning funds. Investigators are still working to identify the attacker. For now, the platform remains frozen, and users are waiting for answers on whether their deposits are safe.




