Ostium oracle exploit drains $18M from Arbitrum RWA protocol
The attacker weaponized a registered forwarder and future-dated oracle reports to mint artificial trading profits, draining the OLP Vault before the team froze trading.
The attacker weaponized a registered forwarder and future-dated oracle reports to mint artificial trading profits, draining the OLP Vault before the team froze trading.
An onchain attacker drained an estimated $18M from Ostium vaults before the protocol halted trading, the latest in a string of DeFi derivatives incidents testing offchain risk engines.
The attacker used Ostium's own Gelato-run price automation against it, forging future-dated oracle reads to extract an $18M USDC payout. It is the second major oracle hit in a week.
Incidents are up but median loss per hack keeps falling, signalling attackers are shifting toward smaller or abandoned protocols while larger venues harden against AI-enabled exploits.
A zeroed oracle signature was the entire vulnerability: one byte in the wrong place let a single attacker borrow against collateral the system could not price, draining the Bonzo money market on…
A single verifier-side price bug let an attacker mint $9M of unbacked borrowing power on Hedera's largest lending market.
The attacker slipped a fake price past Supra oracle verification, borrowing $10M against 250 worthless SAUCE tokens. Nearly all of Hedera's DeFi value walked out the door in 24 hours.
The attacker used a signature-verification bug in Supra's oracle to spoof SAUCE prices, borrow against phantom collateral, and drain roughly $9.05M before the protocol was paused.
One governance takeover, a full chain shutdown, a new AI-focused L1, and an Uniswap burn extension in the same seven days.
Both vendors agree the bug is real on a lab bench; Tangem argues it stays academic because resetting the PIN needs a laser, the card in hand, and rare know-how.
The drained sum is small against Cardano's $87.5B 30-day voting power, but the failure hit the same wallet environment where ordinary ADA holders delegate and cast treasury votes.
Geopolitical escalation is doing what rate-cut optimism could not: pulling capital out of risk and back into USD, with the Fear & Greed Index now deep in extreme fear territory.
Treasury drains via simple on-chain vote have moved from theoretical to routine, and the Bonk memecoin community is the latest proof that low voter turnout is the real attack surface.
Bridge hacks and flash-loan drains are fading, but a single logic flaw in an AI-driven DeFi protocol can now cascade across six chains at once.
A quorum that cleared by 0.3% of supply handed an attacker 99.9% of one vote and 4.43 trillion BONK tokens, the cheapest legal theft the sector has seen.
The profit margin is what stings: roughly $4.4M of spot buying on Bybit and Binance bought just enough quorum to pass a self-serving proposal and walk away with 4.426T $BONK.
A $4M vote-buy blitz executed through a proposal sat dormant for six days, then drained roughly $20M in BONK from the DAO treasury, exposing how thin voting power in a memecoin governance can be.
The exploit rode a passed proposal through BonkDAO's own voting mechanism, a structural hit that turns governance itself into the attack surface.
The $6M loss is a third of the protocol's TVL; the accounting-logic flaw and the unpaused window before guardians acted will get equal scrutiny from audit shops and depositors.
A $65M flash loan inflated a redemption to $70.9M and walked away with $6M, a textbook manipulation of the Lazy Summer Protocol's smart contracts.