A hacker tricked crypto trading platform Ostium with fake price data, stealing $18 million in a growing wave of DeFi attacks.
A hacker just walked away with $18 million from a crypto trading platform called Ostium — not by breaking in, but by feeding it fake information. Here's how it happened, explained simply.
What is Ostium?
Ostium is a DeFi (decentralized finance — financial services run by computer code instead of banks) platform that lets people trade real-world things like gold, currencies, and stock indexes using crypto. It runs on Arbitrum (a fast, cheaper network built on top of Ethereum) and had processed over $50 billion in trades before the attack.
How did the hack work?
To know the real price of gold or a currency, Ostium relies on something called an oracle — a tool that pulls real-world prices onto the blockchain. A piece of software named "PriceUpKeep" pushes those prices in at the right moment.
The attacker gained control of part of this system and submitted fake price reports with future dates on them. This tricked the platform into thinking losing trades were actually winning trades. The result: Ostium automatically paid out $18 million in USDC (a stablecoin — a crypto token designed to always equal $1) from its money pool.
Key facts at a glance:
This isn't a one-off. Just last week, a similar attack drained $6 million from another platform, Summer.fi. These "oracle attacks" keep happening because many DeFi platforms depend on automated systems to feed in prices — and if a hacker can fake that data, they can trick the whole system.
The takeaway: The weak spot in DeFi often isn't the money itself — it's the trustworthy price information the system relies on. Until these price-feeding tools are made more secure, expect more attacks like this.
This is an AI-generated summary. Read the original article at: https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi