← Back

Wire · operational-macro

$23.75 Million Stolen in Off-Chain Oracle Attack and Credential Compromise

Published

21 July 2026

Topic

operational-macro

Sectors

Crypto & Web3

Source

Read at rescana.com

Verified

Fusion42 · 21 July 2026 · Fusion42 review

Ostium DeFi platform lost $23.75 million on 15 July 2026 when an attacker exploited compromised oracle-signer and keeper credentials to submit fraudulent price data, execute leveraged trades against manipulated prices, and drain the liquidity vault. The attacker laundered proceeds through TornadoCash; trading remains frozen while infrastructure is secured.

This Wire brief sits within Fusion42's coverage of Crypto & Web3.

◆ The Wire takeaway

If you're building DeFi infrastructure or trading platforms, off-chain oracles with delegated signer authority are now a proven attack surface worth $24m per hit—and the compromise happens through stolen credentials, not code bugs. You need multi-sig validation on price feeds and real-time anomaly detection, or you're funding the attacker's first move.

Coverage

1 source · 21 Jul 2026

Related on Wire

Topics

Crypto & Web3defi-securityoracle-infrastructurecredential-compromisearbitrumliquidity-risk