High risk — confirmed $23.75M oracle key compromise in July 2026 drained the LP vault; funds unrecovered and laundered through Tornado Cash. Off-chain oracle infrastructure remains excluded from audits and bug bounty, leaving the same structural vulnerability in place.
Risk Breakdown
Top Risks
On July 15, 2026, an attacker compromised the private key for Ostium's oracle signer role (PriceUpKeep), submitted fraudulent BTC prices at $5,000 vs. ~$60,000 real, and drained $23.75M from the OLP vault in 5 minutes. Funds were laundered through Tornado Cash and remain unrecovered. The PriceUpKeep infrastructure was explicitly excluded from all security audits (Zellic 2024, Pashov 2025) and the Immunefi bug bounty.
The exploit exposed a structural audit gap: off-chain oracle infrastructure is a centralized, unaudited critical path. A single compromised private key enabled full control over all price feeds with no circuit breakers in scope of any security review.
Synthetic RWA perpetual payouts depend on LP pool solvency. Post-hack, the OLP vault fell from ~$32.7M to ~$9M (72% drawdown) before recovering to ~$21M on partial redeposits. Sustained LP confidence damage poses ongoing liquidity risk.
Frequently Asked Questions
Is Ostium safe to use?
What are the main risks of using Ostium?
What is Ostium's risk score breakdown?
How does Ostium compare to other Derivatives protocols?
Has Ostium ever been hacked or exploited?
Incident History
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.