ChainThink reports that, according to Ostium's official statement, the core of the attack was a compromise of the off-chain price feed system permissions, not a smart contract vulnerability.
After obtaining off-chain authorization, the attacker exploited a registered legitimate forwarding path in the protocol to submit forged prices of $5,000 and $60,000 to the BTC-USD market, completing an arbitrage cycle of opening and closing positions within the same transaction.
The attacker started with 100 USDC, scaled up through eight transactions, and drained 23.75 million USDC from the OLP treasury within five minutes until the treasury’s circuit breaker was triggered.
The report states that the root cause is the lack of a multi-party approval mechanism in the off-chain infrastructure equivalent to on-chain multisig, creating a single point of access vulnerability. The stolen funds have been converted to ETH and mixed through Tornado Cash; tracking efforts are ongoing.



