Hackers Steal $23.7 M from Ostium Liquidity Vault via Off‑Chain Price‑Feed Manipulation
What Happened — Attackers compromised the off‑chain infrastructure that supplies price data to the Ostium decentralized trading platform. By feeding falsified price reports, they opened and closed large leveraged positions, draining $23.75 million from the liquidity‑provider vault. Trading was paused within an hour; trader collateral remained untouched.
Why It Matters for Compliance & Audit Readiness
- The incident illustrates a classic third‑party risk failure: an off‑chain data feed, often managed by an external provider, became the attack vector. SOC 2 vendor‑management controls (CC6.1, CC6.2) are designed to prevent exactly this.
- Continuous monitoring of third‑party service health and immutable audit logs provide the evidence needed to demonstrate due diligence during a SOC 2 audit.
Who Is Affected — Crypto‑focused financial services platforms, DeFi protocol operators, and any organization that relies on external price‑feed or oracle services.
Recommended Actions
- Map the compromised data‑feed provider to your SOC 2 vendor‑risk controls and verify that contractual security obligations (e.g., right to audit, incident‑response SLA) are in place.
- Implement continuous, automated monitoring of third‑party endpoints and retain immutable logs as audit evidence.
- Conduct a post‑mortem that documents the control gap, remediation steps, and updates to the vendor‑risk assessment process.
Source: BleepingComputer
Technical Notes — The attackers injected malicious price reports into Ostium’s off‑chain oracle layer, then executed rapid trades to siphon USDC from the liquidity vault. Stolen USDC was swapped for ETH and laundered through TornadoCash. No smart‑contract vulnerability was disclosed; the breach stemmed from the off‑chain data pipeline.