Crypto Prices

Ostium identifies off-chain security breach as cause of $23.75 million USDC theft

44 minutes ago
2 mins read
1 views

Ostium Breach Overview

In a detailed post-mortem released this week, Ostium has determined that a significant breach, which led to the misappropriation of $23.75 million USDC from its liquidity vault, stemmed from infiltrated off-chain infrastructure rather than any loophole within its smart contract systems. The investigation revealed that the malicious actor exploited the protocol’s infrastructure to manipulate BTC-USD price reporting, thereby generating illicit trading gains at the expense of the public OLP vault.

Method of Attack

The attacker’s method involved gaining unauthorized entry to the off-chain aspects of the Ostium protocol, without compromising the smart contracts or the multisigs responsible for governance. This conclusion came after Ostium’s team scrutinized their on-chain systems and confirmed that the breach occurred outside their direct control, with no evidence indicating vulnerabilities within their core smart contract implementations.

Crucially, the attacker exploited pathways that Ostium had recognized as legitimate. The scheme initiated with a small test transaction of 100 USDC, which yielded an artificial profit of nearly 898 USDC before the assailant escalated the operation. Following this initial success, the primary set of transactions saw roughly 11.9 million USDC transacted to a designated wallet. Additionally, six subsequent exploit cycles occurred, culminating in a total theft of 23.75 million USDC from the OLP vault.

Investigation Insights

In earlier assessments, blockchain security firm Blockaid speculated that a compromised oracle signer private key facilitated the breach, enabling the attacker to circumvent Ostium’s price verification processes with manipulated reports submitted via a designated PriceUpKeep forwarder. Their investigations suggested that funds amounting to between $11.86 million and $18 million USDC were siphoned off during approximately 20 trading cycles before the attack was intercepted.

Response and Recovery

During the exploit, Ostium’s automated monitoring systems successfully identified the unusual activity in real-time, prompting the protocol to halt trading as investigations unfolded. This preemptive action allowed the team to avoid further losses, and trading eventually recommenced on July 23 following the establishment of enhanced security measures in a new production environment.

Notably, during this incident, trader collateral was safeguarded since user margin remained in the protocol’s trading contracts, unaffected by the compromised liquidity pool. The Ostium team is currently finalizing a recovery strategy to assist liquidity providers who faced losses, with plans to issue a dedicated update soon.

Broader Implications

Though Ostium attributes the exploit to compromised off-chain access, this perspective aligns with Blockaid’s earlier conclusions regarding the attack’s mechanism. The attacker had systematically opened and closed positions through delegated actions, using fraudulent future-dated price reports that appeared legitimate to Ostium, hence generating profits for themselves while inflicting losses on the liquidity vault.

This incident has raised significant concerns regarding the security of the foundational infrastructure that decentralized finance protocols depend on for accessing external market data. It follows closely on the heels of Ostium’s announcement in May about its institutional partnership with Nasdaq, aimed at leveraging the market data to enhance equity perpetual products on its platform. Prior to the breach, Ostium had also achieved a cumulative trading volume exceeding $50 billion and had attracted approximately $27.8 million in investments from notable firms including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute, and GSR.

Popular