Wire · founder news, decoded · opportunities
$23.75 Million Stolen in Off-Chain Oracle Attack and Credential Compromise
◆ Published
21 July 2026
◆ Topic
opportunities
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 21 July 2026 · Fusion42 review
Ostium DeFi platform lost $23.75 million on 15 July 2026 when an attacker exploited compromised oracle-signer and keeper credentials to submit fraudulent price data, execute leveraged trades against manipulated prices, and drain the liquidity vault. The attacker laundered proceeds through TornadoCash; trading remains frozen while infrastructure is secured.
This Wire brief sits within Fusion42's coverage of Fintech. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If you're building DeFi infrastructure or trading platforms, off-chain oracles with delegated signer authority are now a proven attack surface worth $24m per hit—and the compromise happens through stolen credentials, not code bugs. You need multi-sig validation on price feeds and real-time anomaly detection, or you're funding the attacker's first move.
◆ Related on Wire
- Bonzo Lend Loses $9M in Oracle Price Attack12 July 2026
- North Korean hackers stole two-thirds of crypto in 2026: report8 July 2026
- Estée Lauder Data Breach Analysis: Oracle E-Business Suite CVE-2025-61882 Exploitation ...21 July 2026
- Hyperliquid's Lawyers Just Met the SEC Crypto Unit: Here's What Happened15 July 2026
- Critical Oracle EBS bug added to CISA list of exploited vulnerabilities | news | SC Media17 July 2026
- Inside the Institutional Fraud Crisis Plaguing Nigeria's Fintech Sector21 July 2026
◆ Topics
Fintech · defi-security · oracle-infrastructure · credential-compromise · arbitrum · liquidity-risk