Ostium, a decentralized perpetual futures trading platform built on Arbitrum, has confirmed that a $23.75 million exploit earlier this week resulted from a breach of its off‑chain infrastructure, not from smart contract vulnerabilities. The attack targeted the OLP (Ostium Liquidity Provider) vault, draining 23.75 million USDC, while on‑chain contracts and multisig wallets remained secure.
According to the protocol’s post‑mortem, the attacker gained unauthorized access to supporting backend systems and submitted fraudulent BTC‑USD price reports through already‑recognized forwarder paths. These manipulated reports created artificial trading profits, allowing large‑scale withdrawals. The exploit began with a small test transaction of 100 USDC that generated roughly 897.8 USDC in artificial profit, confirming the method’s viability. The main phase then moved about 11.9 million USDC, followed by six additional cycles that brought the total loss to $23.75 million.
Automated monitoring detected the suspicious activity during the attack, and the platform quickly blocked further withdrawals. Ostium emphasised that trader collateral remained secure inside trading contracts and was never exposed. Trading was paused, and the production environment was migrated to a new system with stronger security controls before trading resumed on July 23. The team is now preparing a recovery plan for affected liquidity providers.
The incident highlights a growing concern in DeFi: while on‑chain security has improved, off‑chain infrastructure often remains the weakest link. Ostium’s case underscores the need for comprehensive audits that cover both blockchain and backend components. The platform, which had previously partnered with Nasdaq for equity perpetual products and reported over $50 billion in cumulative trading volume, now faces the challenge of restoring trust and compensating users.