HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Hackers Steal $23.7 M from Ostium Liquidity Vault via Off‑Chain Price‑Feed Manipulation

Attackers compromised Ostium's off‑chain price oracle, feeding false data that let them drain $23.75 million from the platform's liquidity provider vault. The breach underscores the need for robust third‑party risk controls and continuous audit evidence in SOC 2 programs.

LiveThreat™ Intelligence · 📅 July 21, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Hackers Steal $23.7 M from Ostium Liquidity Vault via Off‑Chain Price‑Feed Manipulation

What Happened — Attackers compromised the off‑chain infrastructure that supplies price data to the Ostium decentralized trading platform. By feeding falsified price reports, they opened and closed large leveraged positions, draining $23.75 million from the liquidity‑provider vault. Trading was paused within an hour; trader collateral remained untouched.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates a classic third‑party risk failure: an off‑chain data feed, often managed by an external provider, became the attack vector. SOC 2 vendor‑management controls (CC6.1, CC6.2) are designed to prevent exactly this.
  • Continuous monitoring of third‑party service health and immutable audit logs provide the evidence needed to demonstrate due diligence during a SOC 2 audit.

Who Is Affected — Crypto‑focused financial services platforms, DeFi protocol operators, and any organization that relies on external price‑feed or oracle services.

Recommended Actions

  • Map the compromised data‑feed provider to your SOC 2 vendor‑risk controls and verify that contractual security obligations (e.g., right to audit, incident‑response SLA) are in place.
  • Implement continuous, automated monitoring of third‑party endpoints and retain immutable logs as audit evidence.
  • Conduct a post‑mortem that documents the control gap, remediation steps, and updates to the vendor‑risk assessment process.

Source: BleepingComputer

Technical Notes — The attackers injected malicious price reports into Ostium’s off‑chain oracle layer, then executed rapid trades to siphon USDC from the liquidity vault. Stolen USDC was swapped for ETH and laundered through TornadoCash. No smart‑contract vulnerability was disclosed; the breach stemmed from the off‑chain data pipeline.

📰 Original Source
https://www.bleepingcomputer.com/news/security/hackers-steal-237-million-in-crypto-from-ostium-in-off-chain-attack/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →