Arbitrum bridge not hacked as $24M exploit drains Ostium DEX through oracle manipulation

1 hour ago 1



A brief panic rippled through the Arbitrum ecosystem on July 15 when on-chain watchers flagged a suspicious $24 million USDC withdrawal that looked, at first glance, like a bridge exploit. It wasn’t. Arbitrum’s native bridge remains intact, and the real victim was Ostium, a decentralized exchange focused on real-world asset trading that got drained through a compromised oracle key. The distinction matters enormously. A bridge hack would signal systemic risk across the entire Layer 2 network. An oracle manipulation attack on a single protocol, while painful, is a contained problem. But the roughly $24 million that walked out the door still represents a significant blow, both to Ostium and to confidence in oracle-dependent DeFi protocols. How the attack worked The attacker gained access to a compromised oracle signer private key, specifically one tied to a PriceUpKeep role within Ostium’s system. The falsified reports contained future-dated price entries. The system treated these bogus reports as legitimate, which allowed the attacker to generate phantom profits on positions. Those fake gains were then withdrawn as very real USDC from Ostium’s liquidity vault, known as the OLP. The d...

Read Entire Article