Key Highlights:
  • Ostium says its $23.75 million exploit was caused by compromised off-chain infrastructure.
  • The protocol found no vulnerabilities in its smart contracts.
  • Trader collateral remained safe and a recovery plan is being prepared.

Perpetual trading platform Ostium has released its post-mortem on the July 15 exploit that drained nearly $24 million from its liquidity vault.

According to the investigation, the attacker gained unauthorized access to the protocol's off-chain infrastructure and submitted fraudulent Bitcoin price reports, allowing artificial trading profits to be generated.

The team said there is no evidence that the exploit involved vulnerabilities in Ostium's smart contracts or governance multisigs.

Ostium added that trader collateral was never at risk, trading has already resumed after security upgrades, and a separate recovery plan for affected liquidity providers will be released soon.