Ostium blames off-chain breach for $24 million exploit, rules out smart contract flaw

The team said trader collateral was unaffected and that it will release a recovery plan for liquidity providers.

Ostium blames off-chain breach for $24 million exploit, rules out smart contract flaw

Decentralized perpetuals trading platform Ostium suffered a $24 million exploit that the team has attributed to an off-chain infrastructure breach, according to a post-mortem statement released by the project. Developers confirmed that the attack did not stem from any vulnerability in the platform's smart contracts, drawing a clear distinction between the compromised components and the core on-chain architecture. Trader collateral, the team stressed, remained unaffected throughout the incident.

Ostium operates as a decentralized exchange focused on real-world asset perpetuals, allowing users to trade commodities and forex markets on-chain. The platform's liquidity providers, however, bore the impact of the breach, and the team acknowledged the losses sustained by that segment of its user base. Ostium stated it is actively working on a recovery plan specifically aimed at making liquidity providers whole, though specific details of that plan have not yet been disclosed.

The incident highlights an ongoing vulnerability in decentralized finance protocols that extends beyond smart contract code. Off-chain components — including oracles, backend infrastructure, and administrative systems — have increasingly become attack vectors for bad actors, raising questions about the security assumptions underlying DeFi platforms that market themselves as trustless or decentralized.

Market participants and security researchers will be watching closely for the details of Ostium's recovery plan, as well as any third-party audit findings related to the off-chain systems implicated in the breach.

Source: The Block

Read original article ↗