Onchain perpetuals exchange Ostium said its July 15 exploit, which drained 23.75 million USDC from its OLP vault, stemmed from a compromise of its off-chain infrastructure rather than vulnerability in its smart contracts or protocol multisigs.
In a post-mortem published Wednesday, Ostium wrote that the attacker leveraged unauthorized access to the protocol's off-chain infrastructure to submit fraudulent BTC-USD price reports.
This enabled the attacker to generate artificial trading profits from the public OLP vault.
Ostium said that this initial unauthorized access occurred off-chain.
"Based on our investigation, we have no evidence this incident was a result of a vulnerability in Ostium's smart-contract code logic or a compromise of the multisigs that govern the protocol," the team said.










