And
tags. Let's draft. Lead: On July 15, 2026, an attacker drained roughly $11.86 million in USDC from Ostium, a perpetuals DEX on Arbitrum, by manipulating the BTC/USD price feed. The exploit, which hit the platform's liquidity pool, used a single transaction with 20 calls to flip a position from $5,000 to $60,000. Ostium, backed by General Catalyst and Jump Crypto, had about $63 million in TVL at the time. Then sections. Section 1: "How the exploit worked" - describe the executeBatch, alternating between contracts, price manipulation. Section 2: "The target: OLP" - explain that OLP holds trader collateral and counterparty liquidity, so the loss hits that pool. Section 3: "Oracle setup and the likely flaw" - mention Stork Network for RWA, Chainlink Data Streams for crypto, and that the vulnerability likely lies in authorization to submit price reports or weak freshness checks. Section 4: "A familiar pattern" - mention the Resolv USR exploit in March, where a privileged role could mint without limits. Also mention the receiving wallet opened its first position minutes earlier with a rounding-error deposit, which is a detail. End with the loss is provisional, awaiting Ostium's accounting. We need to avoid any invented quotes. So just paraphrase. Also note that the transaction hash is given, but we can mention it? Probably not necessary, but we can include it as a detail. But careful: we have the hash truncated. We can say "the transaction hash begins with 0x359f8c05…" but that might be too technical. We can skip. We need to write in a human style. Vary sentence length. Use contractions. Let's write. Title: "Ostium Loses $11.86M in USDC to Price Manipulation Exploit on Arbitrum" - that's factual. Slug: "ostium-loses-11-86m-usdc-price-manipulation-exploit-arbitrum" Subtitle: "The perp DEX's liquidity pool took the hit after an attacker gamed the BTC/USD feed with a single transaction." Content: On July 15, 2026, an attacker drained roughly $11.86 million in USDC from Ostium, a perpetuals DEX on Arbitrum, by manipulating the BTC/USD price feed. The exploit, which hit the platform's liquidity pool, used a single transaction with 20 calls to flip a position from $5,000 to $60,000. Ostium, backed by General Catalyst and Jump Crypto, had about $63 million in TVL at the time.
How the exploit worked
The attacker used a single transaction with 20 calls via executeBatch, alternating between Ostium's Trading contract and OstiumPrivatePriceUpKeep. That sequence let them open a BTC/USD position at $5,000 and close it at $60,000 — a move that's clearly unrealistic for the market. The receiving wallet had opened its first position just minutes earlier with a rounding-error deposit, which suggests the attacker was testing the waters before going for the full drain.
The target: OLP
The exploit targeted the Ostium Liquidity Pool, or OLP, which holds trader collateral and counterparty liquidity. That's the pool that takes the other side of trades, so a manipulated price feed can quickly turn a winning position into a loss for the pool. The total loss is provisional, and Ostium hasn't yet published its final accounting.
Oracle setup and the likely flaw
Ostium uses a pull-based oracle system, with Stork Network for real-world asset feeds and Chainlink Data Streams for crypto pairs. The vulnerability likely lies in the authorization to submit price reports or in weak freshness checks — meaning the attacker found a way to get a stale or unauthorized price through. The exact mechanism hasn't been confirmed, but the pattern points to a gap in how price updates are validated.
A familiar pattern
This isn't the first time a DeFi protocol has been hit this way. In March, the Resolv USR stablecoin exploit saw a privileged role mint without limits. While the details differ, both attacks relied on a trusted component being abused. For Ostium, the question now is how quickly it can patch the hole and whether it can recover the funds.
On July 15, 2026, an attacker drained roughly $11.86 million in USDC from Ostium, a perpetuals DEX on Arbitrum, by manipulating the BTC/USD price feed. The exploit, which hit the platform's liquidity pool, used a single transaction with 20 calls to flip a position from $5,000 to $60,000. Ostium, backed by General Catalyst and Jump Crypto, had about $63 million in TVL at the time.
How the exploit worked
The attacker used a single transaction with 20 calls via executeBatch, alternating between Ostium's Trading contract and OstiumPrivatePriceUpKeep. That sequence let them open a BTC/USD position at $5,000 and close it at $60,000 — a move that's clearly unrealistic for the market. The receiving wallet had opened its first position just minutes earlier with a rounding-error deposit, which suggests the attacker was testing the waters before going for the full drain.
The target: OLP
The exploit targeted the Ostium Liquidity Pool, or OLP, which holds trader collateral and counterparty liquidity. That's the pool that takes the other side of trades, so a manipulated price feed can quickly turn a winning position into a loss for the pool. The total loss is provisional, and Ostium hasn't yet published its final accounting.
Oracle setup and the likely flaw
Ostium uses a pull-based oracle system, with Stork Network for real-world asset feeds and Chainlink Data Streams for crypto pairs. The vulnerability likely lies in the authorization to submit price reports or in weak freshness checks — meaning the attacker found a way to get a stale or unauthorized price through. The exact mechanism hasn't been confirmed, but the pattern points to a gap in how price updates are validated.
A familiar pattern
This isn't the first time a DeFi protocol has been hit this way. In March, the Resolv USR stablecoin exploit saw a privileged role mint without limits. While the details differ, both attacks relied on a trusted component being abused. For Ostium, the question now is how quickly it can patch the hole and whether it can recover the funds.


