Onchain perpetuals exchange Ostium said its July 15 exploit, which drained 23.75 million USDC from its OLP vault, stemmed from a compromise of its off-chain infrastructure rather than vulnerability in its smart contracts or protocol multisigs.

In a post-mortem published Wednesday, Ostium wrote that the attacker leveraged unauthorized access to the protocol's off-chain infrastructure to submit fraudulent BTC-USD price reports.

This enabled the attacker to generate artificial trading profits from the public OLP vault.

Ostium said that this initial unauthorized access occurred off-chain.

"Based on our investigation, we have no evidence this incident was a result of a vulnerability in Ostium's smart-contract code logic or a compromise of the multisigs that govern the protocol," the team said.