← Back

Wire · founder news, decoded · opportunities

$23.75 Million Stolen in Off-Chain Oracle Attack and Credential Compromise

Published

21 July 2026

Topic

opportunities

Sectors

Fintech

Source

Read at rescana.com

Verified

Fusion42 · 21 July 2026 · Fusion42 review

Ostium DeFi platform lost $23.75 million on 15 July 2026 when an attacker exploited compromised oracle-signer and keeper credentials to submit fraudulent price data, execute leveraged trades against manipulated prices, and drain the liquidity vault. The attacker laundered proceeds through TornadoCash; trading remains frozen while infrastructure is secured.

This Wire brief sits within Fusion42's coverage of Fintech. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

The Wire takeaway

If you're building DeFi infrastructure or trading platforms, off-chain oracles with delegated signer authority are now a proven attack surface worth $24m per hit—and the compromise happens through stolen credentials, not code bugs. You need multi-sig validation on price feeds and real-time anomaly detection, or you're funding the attacker's first move.

Related on Wire

Topics

Fintech · defi-security · oracle-infrastructure · credential-compromise · arbitrum · liquidity-risk