LIVE · cybersecurity feed
Live wire
security

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. [...]

zeroday.news · 12d ago

Ostium, a decentralized trading platform, has confirmed that an attacker stole approximately $23.75 million from its liquidity provider vault last week. The incident, which Ostium described as an attack on its off-chain infrastructure, involved the manipulation of price feeds to generate illicit profits.

The platform, built on the Arbitrum blockchain, uses external data feeds to supply prices for trading traditional and crypto assets. The attacker reportedly submitted fraudulent price reports, which were disguised as legitimate, and then rapidly opened and closed large positions to accumulate artificial gains.

Ostium first alerted its community to a security incident on July 16, announcing that trading had been paused. At that time, the company stated that relevant authorities had been notified and that efforts were underway to track the movement of the stolen funds.

In a subsequent update, Ostium clarified that the attack specifically targeted the off-chain infrastructure responsible for feeding prices into the protocol. The company emphasized that trader collateral, held in a separate smart contract, was not affected. Existing long and short positions also remain open and were not liquidated, though they are currently frozen due to the trading pause.

Blockchain security firm PeckShieldAlert reported that the exploiter converted the stolen USDC into 12,080 Ethereum. Following this, 10,540 Ethereum was deposited into Tornado Cash, a cryptocurrency mixer, in an apparent attempt to obscure the transaction trail.

Trading on the Ostium platform remains paused, five days after the initial incident. Ostium has committed to providing at least 24 hours' notice before resuming operations, at which point existing positions will be marked to the reopening price. The company has also promised to release a post-mortem analysis with technical details in the coming days, as it works to secure the compromised infrastructure and determine a path forward for liquidity providers.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.