- Ostium paused trading after an apparent $18 million exploit.
- Attackers allegedly manipulated oracle data to drain a vault.
- Stolen USDC was converted into ETH and moved across multiple wallets.
- The platform is investigating while trading remains suspended.
Onchain perpetual trading platform Ostium has suspended trading after suffering an apparent exploit that drained roughly $18 million from one of its vaults on Arbitrum.
Blockchain security firm Blockaid said the attacker abused authorized oracle reports to generate artificial trading profits, triggering a large payout from the platform's OLP vault. Shortly after the exploit, the attacker converted portions of the stolen USDC into ETH before distributing the funds across multiple wallets.
Ostium confirmed it was aware of the incident and immediately halted trading while its team investigates the exploit.
The attack comes only weeks after Ostium announced a partnership with Nasdaq to support equity perpetual products and after the platform reported more than $50 billion in cumulative trading volume. The incident adds to a growing list of major DeFi exploits targeting blockchain infrastructure and oracle systems.