Ostium attack review, off-chain oracle permissions stolen, forged BTC price arbitrage of 23.75 million USDC
According to the official report from Ostium, the core of this attack lies in the intrusion of the off-chain price reporting system's permissions, unrelated to smart contract vulnerabilities. After gaining off-chain authorization, the attacker submitted forged prices (5,000 USD and 60,000 USD) to the BTC-USD market using the legally registered forwarding paths of the protocol, completing an atomic open-close arbitrage cycle within the same transaction, and starting with a rolling scale of 100 USDC. Through 8 transactions, they extracted 23.75 million USDC from the OLP treasury within 5 minutes, until the treasury's circuit breaker mechanism was triggered.
The root cause is the lack of a multi-party approval mechanism at the same level as on-chain multi-signature in the off-chain infrastructure, creating a single point of permission vulnerability. The stolen funds have been converted to ETH and mixed through Tornado Cash, and tracking efforts are still ongoing.






