Friday, August 7, 2026 Today's news About Live prices →
£ PoundToken
Crypto, covered properly · Est. 2026
DeFi

Compromised oracle key drains $18m from Ostium’s RWA perpetuals vault

Blockaid says a hijacked price-feed signer let an attacker fake trade profits on Arbitrum-based Ostium, reviving concerns over oracle security in tokenised markets.

By Rajesh Patel · ·3 min read
Compromised oracle key drains $18m from Ostium’s RWA perpetuals vault

Ostium, a decentralised exchange offering perpetual futures on real-world assets, halted trading on 11 July after an attacker compromised the private key of an oracle signer and drained roughly $18 million in USDC from the protocol’s liquidity vault, according to blockchain security firm Blockaid. The incident is one of a growing number of 2026 exploits in which attackers have targeted privileged access to price-feed infrastructure rather than smart-contract code itself.

Blockaid, which flagged the breach publicly, said the attacker gained control of a registered “PriceUpKeep” forwarder used to submit authorised oracle reports, and used it to file price updates dated into the future. That manipulation of the feed allowed the attacker to book fictitious trading profits, which Ostium’s vault then paid out in genuine USDC. Ostium, which runs on Arbitrum and markets itself as a venue for trading tokenised real-world asset exposures, paused trading platform-wide while it investigates the breach.

Oracle governance, not code, is the weak link

The Ostium incident underlines a structural vulnerability that has increasingly troubled institutional observers of decentralised finance: many protocols depend on a small number of privileged signing keys to feed external price data on-chain, and a single compromised key can undermine an otherwise sound smart-contract system. Unlike exploits that stem from bugs in deployed code, this attack exploited legitimate, authorised infrastructure — precisely the kind of operational risk that audits of contract logic are not designed to catch.

For European and UK institutions weighing exposure to tokenised real-world assets, the episode is a reminder that the security perimeter of such platforms extends well beyond their smart contracts to the operational controls — key custody, signer authentication and monitoring — surrounding their oracle infrastructure. As tokenisation pilots involving major custodians and clearing houses expand, the standards applied to oracle governance are likely to draw closer scrutiny from both institutional counterparties and regulators.

Part of a wider pattern in 2026

Cryptopolitan, which also reported the breach, described the Ostium exploit as part of a wave of 2026 incidents tied to compromised privileged access rather than novel contract-level bugs. Both outlets converged on the central mechanics: a hijacked oracle signer key, forward-dated price submissions, and a vault that paid out USDC against manipulated, illegitimate trades.

Ostium had not, as of publication, confirmed the precise final loss figure or set out a remediation timeline; Blockaid’s estimate of nearly $18 million was corroborated across reports, with one account citing a range extending to as much as $20 million. The protocol has not disclosed whether the compromised key belonged to an internal signer or a third-party keeper service, nor whether affected users will be made whole.

Read more: Avalanche tokenised asset value jumps to $2.1bn on $11bn Bridgetower deal

Sources

More DeFi