Share on XShare on LinkedInShare on Telegram
Hack Analysis

Ostium $23.75M Price Report Signer Compromise Exploit (Explained)

A compromised off-chain price-signing system let an attacker submit forged yet validly signed price reports, opening and closing leveraged trades that drained $23.75M from Ostium's OLP vault.

Author
QuillAudits Team
July 21, 2026
Ostium $23.75M Price Report Signer Compromise Exploit (Explained)
Share on XShare on LinkedInShare on Telegram

On July 15, 2026, Ostium lost 23,752,746 USDC when its OLP vault, the liquidity pool that backs every trader's profit and loss, was drained by an attacker exploiting the protocol's price-reporting pipeline. This was not a reentrancy bug, not a flash-loan attack, and not a bridge exploit. The attacker's own trading capital was negligible, the exploit ran almost entirely on leverage against a price feed that should never have been trusted. The real point of failure sat off-chain, in the infrastructure responsible for signing the price reports Ostium's contracts rely on to settle trades.

Protocol Background

Ostium is a synthetic perpetuals trading protocol on Arbitrum. Traders open leveraged positions through the Trading contract, 0x6D0bA1f9996DBD8885827e1b2e8f6593e7702411, and its companion TradingCallbacks contract, 0x7720fC8c8680bF4a1Af99d44c6c265a74e9742a9. Settlement pulls from a shared pool, the OLP vault,  0x20d419a8e12c45f88fda7c5760bb6923cee27f98, which backs trader profit across the whole platform. Prices used to open, close, and liquidate positions arrive as signed price reports from an off-chain reporting system. The PriceUpKeep contract,  0xB71ec9eBD8145daCaCF6724363143cb5667A3d36, and the Verifier contract,  0xd456939e54F68Ef9B0BE62aBB2EC4A37397Cb814, check that a submitted price report carries a valid signature from an address in an authorized-signer list before the Trading contract acts on it. That signature check is the entire gate. Trader margin sits in a separate, isolated contract from the OLP vault, a distinction that matters later.

Hack Analysis

On July 15, attacker's trading account, 0x321df194646029e7a6193ea05573d4b9c398bfd9, opened a leveraged position on Ostium's Trading contract, routed through a separate delegate controller EOA, 0xd1794196f0fc99c7f27970e661597d77d9a85869. Neither wallet held anything close to the capital needed to move a market this size, the position's size came entirely from leverage.

ostium-1.pngostium-2.png

The same transaction that opened the position also triggered a call into the PriceUpKeep contract, submitting a price report for the Verifier contract to check.

ostium-3.png

When the Verifier recovered the signing address from that price report, it matched an entry in the contract's own  isAuthorizedSigner  mapping,  0x38110430184c22d93c30b3e67b9af98d5d0ab8bd, so the report passed as legitimate. The price itself did not reflect any real market condition, it reflected whatever number the attacker needed to make the trade profitable.

ostium-4.png

With a validated but manipulated price now on record, the attacker's position was opened and closed almost immediately against it, realizing a profit with no corresponding real market exposure. Because the price report carried a genuine signature, the Trading and TradingCallbacks contracts had no reason to treat the trade as anything but ordinary.

ostium-5.png

The attacker repeated this open-and-close pattern in a loop, each cycle pulling more of the same artificial profit out of the OLP vault. By the time the pattern ran its course, the loop had drained 23,752,746 USDC from the vault. Ostium's own account of the incident places the active exploitation window between 14:18 and 14:23 UTC that day, a span of about five minutes for the entire drain.

ostium-6.png

Root Cause

This was not a bug in Ostium's trading logic, its accounting, or its smart-contract access control. The root cause was a compromise of the off-chain infrastructure responsible for signing Ostium's price reports, which let the attacker produce a validly signed price the on-chain Verifier had no way to distinguish from a legitimate one.

  • A single authorized signer's output was sufficient to move the price the entire trading and settlement pipeline relied on, with no secondary check against an independent reference price before a report was accepted.
  • Nothing in the Verifier or PriceUpKeep flow constrained how far a submitted price could deviate from recent market prices, so a valid signature was treated as equivalent to an economically valid price.
  • The open-and-close pattern generated realized PnL almost instantly, and no rate limit or anomaly check flagged the repeated loop before the vault was drained.

Ostium's public updates describe the compromise only as affecting the off-chain infrastructure feeding prices into the protocol. The specific initial entry point, whether a leaked signing key, a breached server, or something else, has not been made public as of this report.

How QuillAudits Could Have Prevented This

Independent price-deviation checks. A bounds check comparing every incoming price report against a reference feed, such as a DEX TWAP or a secondary independent reporter, before the Verifier accepts it would have rejected a price with no basis in real market conditions, regardless of whether the signature checked out.

Signer-threshold requirements. Requiring price reports to carry signatures from more than one independent authorized signer, rather than accepting any single signature from the isAuthorizedSigner set, removes the single point of compromise the attacker relied on.

Anomaly detection on open-close cycles. Flagging or rate-limiting rapid open-and-close position pairs realizing outsized PnL in a short window would have surfaced the loop after the first cycle instead of letting it repeat until the vault was empty.

Key custody hardening for signing infrastructure. Isolating and hardening the systems and credentials that generate signed price reports, separate from general application infrastructure, reduces the chance that a single infrastructure compromise translates directly into a forged, validly signed price.

Funds Flow After Attack

The 23,752,746 USDC drained from the OLP vault was swapped to ETH via KyberSwap and subsequently distributed across more than a dozen wallets. The funds are now being deposited into Tornado Cash.

ostium-7.pngostium-8.png

Post-Attack Mitigation

Ostium told its community the OLP vault had an issue and that all trading had been paused while the team looked into it.

Ostium confirmed trader funds and open positions were safe, with the trading storage contract frozen and the investigation continuing alongside outside help.

Ostium's Co-founders & CEO said the exploit ran for about five minutes, from 14:18 to 14:23 UTC, and that trading was paused within the hour while the team coordinated with law enforcement and outside security researchers.

Ostium reiterated that trading remained paused, positions stayed unmodifiable, and trader margin sat untouched after fourteen hours of continuous coordination with authorities and researchers.

Ostium confirmed the final loss of 23,752,746 USDC and explained that a compromised off-chain price-signing system let the attacker submit manipulated but validly signed prices to drain the vault, while trader collateral stayed safe in its separate, isolated contract.

Ostium said it was aiming to relaunch trading within the week, with positions marked to the live price at reopen and a recovery plan underway for affected liquidity providers.

Relevant Addresses and Transactions

Attacker Wallets / EOAs

Post-Swap ETH-Holding Wallets and Tornado Cash Depositors

Vulnerable / Main Contracts

Compromised Keys / Signers

Key Transactions

Conclusion

No smart-contract bug was exploited and no cryptography was broken here. What failed was trust in a single off-chain signer, and once that signer was compromised, a valid signature was enough to make a fabricated price look real. Trader collateral survived because it sat in an isolated contract, but the OLP vault's 23,752,746 USDC did not have the same protection. A signature only proves who signed a price report, not that the price itself was true.

Contents

Tell Us About Your Project
Subscribe to Newsletter
hashing bits image
Loading...
cta-bg

WE SECURE EVERYTHING YOU BUILD.

From day-zero risk mapping to exchange-ready audits — QuillAudits helps projects grow with confidence. Smart contracts, dApps, infrastructure, compliance — secured end-to-end.

QuillAudits Logo


ISO 27001
DeFi Security AllianceplumeUniswap FoundationAethiropt-collectivePolygon SPNBNB Chain Kickstart

All Rights Reserved. © 2026. QuillAudits - LLC