An attacker used a registered PriceUpKeep forwarder and future-dated authorized oracle reports to create artificial trade profit, triggering a ~$18M USDC payout from the vault. More details in 🧵
— Blockaid (@blockaid_) July 15, 2026
According to Blockaid, the attacker did not rely on a conventional smart contract vulnerability. Instead, the exploit combined two legitimate protocol components in an unintended way.
Since these reports were already approved, the exploit skirted regular expectations of data integrity. The incident shows the danger of an attack surface that is trusted oracle infrastructure that does not include abnormal input in validation logic.
Ostium is a decentralized perpetual trading protocol which helps individuals enter the real-world asset (RWA) markets without requiring access to a centralized hub of a central authority.
The project has garnered significant support from cryptocurrency and venture capital investors such as General Catalyst, Jump Crypto, Coinbase Ventures, Wintermute and GSR, with them raising around $27.8 million to invest in the development.
Platforms that process RWAs are becoming more appealing to malicious attackers, as institutions begin to see the value in tokenizing their assets and rely on complex pricing mechanisms for them.
The Ostium incident is a reminder that while smart contract code is critical, it’s not all that’s needed for a successful decentralized finance project. Today, protocol security no longer just relies on Oracle systems, automation applications, and off-chain data verification.
Most popular DeFi apps use external price feeds and automated execution services to execute trades and determine balances for users. If such systems can be exploited via legitimate, but badly handled inputs, attackers can steal money without exploiting common coding weaknesses.
As DeFi protocols grow to institutional-level products and tokens representing real-world scenarios, it is vital to ensure their oracles and execution methods are properly validated to safeguard investors’ funds, said the exploit.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
