๐จ EXPLOIT ALERT ๐จ
@Ostium on #Arbitrum has just been exploited for ~$11.86M USDC, draining roughly 32% of the vaultโs $34.3M TVL.
๐ How it happened:
The attack stems from a Private Key Compromise (Oracle Signer) resulting in price manipulation.
A compromised privileged key allowed the attackerโs smart account to act as a registered forwarder. By submitting highly favorable price reports signed by the compromised, authorized oracle, they bypassed the OstiumVerifier.verify() checks.
The attacker then executed 20 loops of delegatedAction โก๏ธ openTrade + performUpkeep(closeTradeMarket). By feeding these self-signed favorable prices, they were able to instantly open and close trades at a massive profit, siphoning funds from the $oLP vault.
๐ On-Chain Details:
Loss: 11,862,445 USDC
Attacker: 0xD1794196f0fc99c7f27970e661597d77d9a85869
Victim (Vault): 0x20d419a8e12c45f88fda7c5760bb6923cee27f98
Exploit Tx:
https://t.co/CFNLeorE4J
Stay safe out there! ๐ก๏ธ
#DeFi #Web3Security #CryptoAlert #Arbitrum #HackAlert