Today, the DeFi market faced another serious incident: Ostium, a perpetual contracts platform for real-world assets operating on the Arbitrum network, lost nearly $18 million in USDC. The cause was a hack of the oracle signer's key, allowing the attacker to manipulate prices and drain a significant portion of the liquidity pool.
As I discovered during analysis, the attacker compromised the private key of the oracle signer, enabling them to bypass standard checks and send fake price predictions to the protocol. Using the registered PriceUpKeep forwarder, the hacker executed about 20 repetitive transactions through delegated actions, gaining instant profit at the protocol's expense without actual trading involvement.
One-third of funds withdrawn from the vault in a few hours
According to on-chain analysis, approximately $11.86 million to $18 million in USDC was withdrawn from the vault. This accounts for about 28% of the total value locked (TVL), which stood at $63 million at the time of the attack. The main transaction can be verified via Arbiscan. Multiple cycles of opening and closing positions allowed the hacker to quickly deplete the liquidity pool.
Ostium is a major decentralized exchange for perpetual contracts on real-world assets (stocks, commodities, currencies, and indices), which raised approximately $27.8 million from leading investors, including General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute, and GSR.
Serious blow to the reputation of RWA protocols
Despite strong institutional backing and several completed audits, the incident highlights the vulnerability of protocol infrastructure dealing with real-world assets (RWA) and relying on oracles. The investigation is ongoing, and users are strongly advised to monitor official channels for withdrawal instructions and security updates.
My expert opinion: This hack is yet another reminder that the perpetual contracts sector for real-world assets, despite rapid growth, remains extremely vulnerable to attacks on private keys and oracle infrastructure. Projects need to implement multi-layered key protection and real-time monitoring; otherwise, such incidents will undermine trust in the entire RWA ecosystem.