An update on where things stand:
What happened
On July 15, Ostium’s LP (liquidity provider) vault was exploited for 23,752,746 USDC. Based on our ongoing investigation, the attacker compromised off-chain infrastructure related to the system that feeds prices into the protocol. The attacker then submitted illegitimate price reports that were manipulated to appear as valid, opening and instantly closing a series of large positions to extract an artificial profit from the vault. By design, trader collateral sits in a separate, isolated contract and is not affected, with all positions remaining open.
Our response
We are working with Mandiant, zeroShadow, Collisionless, and SEAL 911, alongside law enforcement, and coordinating with exchanges, bridges, and stablecoin issuers. Within 60 minutes of the first exploit transaction, we coordinated to pause trading and freeze all trading contracts. Currently, all of our engineering efforts are focused on isolating and hardening the infrastructure needed to enable a secure re-launch.
What is next
Impacted liquidity providers and the safe resumption of trading remain our top priority, and we are working around the clock towards the path forward. As a reminder, we will give at least 24 hours notice before trading contracts are unfrozen. Upon re-open, trader positions will be marked to the price at re-open, independent of interim price movements.
Please trust only official channels. We will never DM you first or ask for your keys, seed phrase, or funds.
If you have any leads, information, or resources to help with the investigation, reach us at: TIPS@ostium.io.