Ostium Protocol Loses $18 Million in Timestamp Manipulation Attack

Key Takeaways Decentralized trading platform Ostium on Arbitrum suffered a security breach resulting in losses between $18 and $22 million. The perpetrator exploited the platform’s oracle mechanism by submitting price data with falsified future timestamps. Fraudulent trades appeared profitable due to the manipulation, causing the liquidity vault to dispense $18 million in USDC. All trading activity has been suspended as Ostium conducts a thorough investigation, with users advised to revoke smart contract permissions. This incident continues a troubling trend of oracle-related vulnerabilities affecting DeFi platforms in 2025 and 2026. On July 15, Ostium—a decentralized perpetual futures platform operating on Arbitrum—suspended all trading operations following a sophisticated attack that resulted in approximately $18 million in USDC being withdrawn from its liquidity reserves. RWA Perpetual Protocol Ostium Suffers Suspected $18 Million Exploit on Arbitrum Security firm Blockaid said it detected an exploit involving Ostium Vault on Arbitrum. According to Blockaid, the attacker used a registered PriceUpKeep forwarder and future-dated authorized oracle… pic.twitter.com/2DfIGrRIoR — Wu Blockchain (@WuBlockchain) July 15, 2026 Multiple blockchain security organizations, including Blockaid and CertiK, detected and reported the breach. While Blockaid assessed the damage at approximately $18 million, CertiK’s analysis suggested the total could reach $22 million. Ostium’s team has acknowledged the incident but has yet to release official loss figures pending their ongoing investigation. The vulnerability exploited in this attack centered on Ostium’s oracle infrastructure—the critical system responsible for feeding external market price information to the decentralized platform. Blockaid’s analysis revealed that the attacker leveraged a legitimate component within Ostium’s automated pricing mechanism known as the PriceUpKeep forwarder. This module functions as the gateway for transmitting real-time asset valuations onto the blockchain during trade execution. The malicious actor submitted oracle price updates containing fabricated timestamps set to future dates. This temporal manipulation caused unprofitable positions to register as successful trades, subsequently prompting the vault’s smart contract to release approximately $18 million in USDC. In a statement shared on X, Ostium announced the immediate suspension of trading following the detection of irregularities in its vault system. The platform emphasized user protection, stating: “With user security being our first concern, we recommend that all users temporarily revoke approvals for our contracts until we can further investigate the recent incident.” Technical Details of the Oracle Breach Ostium’s pricing infrastructure relies on Gelato, an external automation service, to deliver real-world asset valuation data to the blockchain. The PriceUpKeep smart contract serves as the central mechanism coordinating these price refresh operations. The attacker successfully obtained access to an authorized position within this framework, enabling them to introduce counterfeit pricing information with incorrect timing parameters. This manipulation deceived the protocol into validating false profitable positions, triggering unauthorized fund releases from the treasury.
عنوان اصلی (انگلیسی): Ostium Protocol Loses $18 Million in Timestamp Manipulation Attack
مشاهدهی خبر کامل در منبع ↗ بازگشت به Perpetual Protocolاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.