Attacker drains $18M USDC from Ostium's vault using future-dated oracle reports and registered PriceUpKeep forwarder


๐/@blockaid_ โข
Revision history
2 recorded changes
Want your article here?
Promote with Leviathan News

2 recorded changes
Want your article here?
Promote with Leviathan NewsAn attacker used Ostium's registered PriceUpKeep forwarder and future-dated authorized oracle reports to fabricate profitable trades, draining roughly $18M USDC from its Arbitrum vault. Because the reports arrived through Ostium's authorized price pipeline, the vault accepted fake PnL as valid and paid it out in USDC.
TLDR by @Benthic

The Block ยท

๐/@pear_protocol ยท

๐/@turnkeyhq ยท

๐/@avax ยท

๐/@kamino ยท

๐/@0xCster ยท

The Block ยท

๐/@pear_protocol ยท

๐/@turnkeyhq ยท

๐/@avax ยท

๐/@kamino ยท

๐/@0xCster ยท
๐ Love DeFi? Ready to dive in and start earning $SQUID while making an impact?