Hackers steal $23.7 million in crypto from Ostium in off-chain attack
An attacker stole $23.75 million in cryptocurrency from the Ostium trading platform by compromising off-chain infrastructure that supplies price data to the protocol. The theft targeted the liquidity provider vault. No specific software versions or patches have been disclosed. The incident highlights risks associated with off-chain components in decentralized finance platforms.
AI Analysis
Technical Summary
The Ostium trading platform suffered a theft of $23.75 million from its liquidity provider vault due to a compromise of off-chain infrastructure responsible for feeding price information into the protocol. This off-chain attack allowed the attacker to manipulate or exploit the price feeds, resulting in the loss of funds. No detailed technical information about the vulnerability or exploited mechanism is provided. There is no indication that this is a vulnerability in the on-chain smart contracts themselves, but rather in the supporting off-chain systems.
Potential Impact
The attacker was able to steal a significant amount of cryptocurrency ($23.75 million) from Ostium's liquidity provider vault. This represents a direct financial loss to the platform and its users. The compromise of off-chain infrastructure undermines trust in the price feeds and the integrity of the protocol's operations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since this attack exploited off-chain infrastructure, Ostium and similar platforms should review and strengthen the security of their off-chain components, including price feed mechanisms. No official fix or patch information is available at this time.
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
Description
An attacker stole $23.75 million in cryptocurrency from the Ostium trading platform by compromising off-chain infrastructure that supplies price data to the protocol. The theft targeted the liquidity provider vault. No specific software versions or patches have been disclosed. The incident highlights risks associated with off-chain components in decentralized finance platforms.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Ostium trading platform suffered a theft of $23.75 million from its liquidity provider vault due to a compromise of off-chain infrastructure responsible for feeding price information into the protocol. This off-chain attack allowed the attacker to manipulate or exploit the price feeds, resulting in the loss of funds. No detailed technical information about the vulnerability or exploited mechanism is provided. There is no indication that this is a vulnerability in the on-chain smart contracts themselves, but rather in the supporting off-chain systems.
Potential Impact
The attacker was able to steal a significant amount of cryptocurrency ($23.75 million) from Ostium's liquidity provider vault. This represents a direct financial loss to the platform and its users. The compromise of off-chain infrastructure undermines trust in the price feeds and the integrity of the protocol's operations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since this attack exploited off-chain infrastructure, Ostium and similar platforms should review and strengthen the security of their off-chain components, including price feed mechanisms. No official fix or patch information is available at this time.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/hackers-steal-237-million-in-crypto-from-ostium-in-off-chain-attack/","fetched":true,"fetchedAt":"2026-07-20T22:26:48.511Z","wordCount":760}
Threat ID: 6a5ea0a82a4a8d5989daab12
Added to database: 07/20/2026, 22:26:48 UTC
Last enriched: 07/20/2026, 22:27:02 UTC
Last updated: 07/21/2026, 09:22:28 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.