Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Ostium trading platform loses $23.75 million in off-chain exploit

The Ostium decentralized trading platform suffered a $23.75 million loss due to an attacker compromising its off-chain price feed infrastructure. The attacker manipulated these external data feeds to submit illegitimate price reports, then executed rapid trades to generate artificial profits. This incident underscores the critical risks associated with off-chain oracles in DeFi protocols, though on-chain user collateral and positions remained secure in separate contracts.
Read Full Article →

Threat Intelligence Ostium trading platform loses $23.75 million in off-chain exploit July 21, 2026 Share By SC Staff (Adobe Stock) The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week after compromising off-chain infrastructure used to feed prices into the protocol, according to a recent report by Bleeping Computer. The attacker manipulated illegitimate price reports to disguise them as valid ones, then rapidly opened and closed large positions to generate artificial profits. Trader collateral and existing positions were not directly affected, as they are held in separate contracts. Ostium, a decentralized trading platform on Arbitrum, uses external data feeds for prices, which were compromised in this incident. The stolen USDC was swapped for Ethereum and sent to TornadoCash, a cryptocurrency mixer. Trading on the platform remains paused, with Ostium promising at least 24 hours' notice before operations resume and a post-mortem analysis to follow. The incident highlights the vulnerability of off-chain infrastructure in decentralized finance protocols. Source: Bleeping Computer SC Staff Related Threat Intelligence Sophisticated crypter service Cruciferra evades detection with advanced techniques SC Staff July 21, 2026 Cruciferra, first offered for sale in autumn 2025, underpins dozens of campaigns delivering malware such as AsyncRAT, Agent Tesla, and Remcos. Threat Intelligence HollowGraph malware uses Microsoft 365 calendar for command and control SC Staff July 20, 2026 HollowGraph, believed to be part of the Cavern command-and-control framework, targets organizations in Israel for espionage purposes. Threat Intelligence HelloNet campaign abuses ViPNet update mechanism to target Russian organizations SC Staff July 20, 2026 The HelloNet campaign targets organizations using ViPNet, a Russian information-security product suite commonly used in government and regulated environments. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Backdoor Deauthentication Attack Denial of Service Distributed Scans Domain Hijacking Fault Line Attacks Hybrid Attack Password Cracking Reconnaissance You can skip this ad in 5 seconds

Share this article