Ostium's vault is still $19m short, and its LP token still says $1.15
Fifteen days after an attacker took $23.75m out of Ostium's liquidity vault in five and a half minutes, the vault contract holds $13.4m of USDC against $34.3m of LP claims.
Listen to this article

A liquidity provider who opens the Ostium app today sees an oLP token worth 1.1500 USDC. Fifteen days ago, in the minutes before an attacker emptied most of the vault behind that token, it read 1.1492. The price has gone up.
The vault contract itself tells a different story. Read directly from Arbitrum this morning, it holds $13,412,076 of USDC. The 29,800,985 oLP tokens outstanding against that balance carry a combined claim of $34,270,766 at the quoted price. That is 39 cents of vault money for every dollar of claim, where the same two figures on 15 July stood at 96 cents.
Both numbers are true, and the distance between them is the whole of the Ostium story now. Ostium Labs has said it will make affected liquidity providers whole, contributing from its own balance sheet alongside new and existing partners, and promised a follow-on post setting out “the structure and allocation of the capital commitment”. That post has not appeared. The vault’s own accounting still carries $19.2m of the theft.
Five minutes and twenty-nine seconds
Between 14:18:23 and 14:23:52 UTC on 15 July, eight transactions moved 23,753,539 USDC out of the Ostium Vault into a single wallet. Ostium put the loss at 23,752,746 USDC, which is the same figure to within about $800. The vault’s balance fell from $32,711,853 to $8,959,307 in those five and a half minutes: 72.6% of it, gone.
Each transaction ran the same loop against the perpetuals engine. Twenty-four price reports were submitted through Ostium’s PrivatePriceUpKeep contract, and every single one named BTC/USD at exactly 5,000.000000000000000000 or exactly 60,000.000000000000000000. A long was opened at the low figure and closed at the high one, and the vault paid the difference.
The first stake was 100 USDC, which came back as 897.80 plus the margin. Then 1,000. Then 9,000, 80,000, 700,000 and 530,000 inside a single transaction, then 1,500 twice, then 500,000, 400,000, 300,000 and 120,000. Twelve rounds, and every one of them returned 8.987 times the stake.
That constant is Ostium’s own risk control. The protocol caps a take-profit order at 900% above entry, and applies the cap automatically when a trader sets none. A move from $5,000 to $60,000 is worth 1,100%, so the cap truncated each round to roughly a tenfold return, and the attacker responded by putting more money in rather than trying to beat it. Working capital was never a constraint after the second round; the vault was funding the stakes.

Neither price was real
The widely repeated version of this attack has a fake price of $5,000 on the way in and the real market price of about $60,000 on the way out. The market disagrees. On Coinbase, the one-minute candle covering 14:18 UTC on 15 July opened at $65,231 and closed at $65,264, with a low of $65,188. Bitstamp’s book sat within a few dollars of that.
Bitcoin was near $65,250. Both of the prices the attacker submitted were invented, one absurdly and one plausibly, and the plausible one is the more interesting of the two: a report that reads like a real quote is the one an operator watching a dashboard is least likely to catch.
The reports were not replayed captures, either. Each carried a timestamp equal to the timestamp of the block that included it, from 14:18:23 through to 14:23:52. Whoever was submitting them could produce a fresh, correctly signed report on demand, five and a half minutes into an attack, which is the definition of holding the signing capability rather than an old signature. Ostium’s account matches: the attacker “compromised off-chain infrastructure related to the system that feeds prices into the protocol”, then “submitted illegitimate price reports that were manipulated to appear as valid”.
Ostium’s documentation describes an in-house consensus oracle in which “multiple independent publishers each pull in the underlying market feeds and compute the price, then cryptographically sign it”, with those signatures “reconciled into a single agreed price”. A design built to survive one dishonest publisher produced twenty-four reports at $5,000 and $60,000.
The tranche that was supposed to take this
Ostium sells its vault on subordination, and does so in the language of structured credit. OLP is the senior tranche. A junior buffer, “posted by Ostium affiliates and strategic partners”, absorbs trader profit and loss “first, in full, before any trading loss can reach OLP”, the same waterfall used in collateralised loan obligations and clearinghouse defaults.
The documentation also states where that protection stops. It covers “trading losses and operational challenges with offchain hedging”. Then: “Because OLP is held onchain, a security event affecting onchain funds is borne first by onchain capital, including OLP, and OLP deposits are not insured.”
So the tranche structure inverts for exactly this event. In a trading loss the buffer stands in front of the LPs. In a theft the LPs are at the front, because the money a thief can reach is the money sitting in the contract, and that is theirs. The USDC that left on 15 July left the vault contract itself.
There is a mechanical consequence visible today. Ostium framed the deposit freeze as protection for the LPs who stayed, so that they “continue to earn a share of protocol revenue on a smaller capital base”. The documentation gives the other reason: when losses begin drawing on OLP capital the vault enters its undercollateralised state and “automatically blocks new deposits” as an accounting measure, because deposits against a pending loss create share-pricing ambiguity. Both statements are accurate. Only one of them is optional.
Because oLP price recomputes once a day at settlement and the exploit loss sits in the vault’s pending-loss counter rather than in the price, the quoted figure has carried on accruing fees through all of this. The counter is the honest number: it jumped by $23,753,343 on 15 July, and it has fallen back by $4,544,558 since, which is trading revenue paying the hole down. $19.2m of it remains.
What has moved since the reopen, and what has not
Trading resumed at 10:00 ET on 23 July, in stages, protective and reduce-only actions first, with every open position marked to the price at the reopen rather than to anything that happened during the eight-day pause. Trader collateral was never touched; it sits in a separate contract, which is the one part of the design that did what it promised.
Three things are visible on-chain since.
The vault’s USDC balance has risen from $8.96m to $13.41m. All $5.88m of the inflow arrived from Ostium’s own TradingCallbacks contract, which is settlement and fee flow. No transfer of $400,000 or more has come into the vault from an outside address, so the capital commitment has not landed here.
Not one oLP token has been minted or burned since 14:18 on 15 July. The supply is identical to the digit: 29,800,984.705882. Deposits are frozen and no depositor has been redeemed, which is what “withdrawals will process at the next settlement” has amounted to in practice.
And traders have taken money off the table. USDC held across Ostium’s two custody contracts, the vault and TradingStorage, came to $63,362,102 minutes before the attack. It is $26,014,183 now, a fall of 59%. Some of that is the theft. The rest is departure, at a protocol that had processed $50bn of cumulative volume, earned $35m of protocol revenue and served more than 26,000 traders by the end of April, and that holds a real position in tokenised real-world assets.
Six audits and a component nobody was allowed to test
Ostium’s contracts have been through six security reviews: Zellic in February 2024 and November 2025, ThreeSigma in early 2024, and Pashov Audit Group in January 2025, April 2025 and January 2026. Zellic found no critical vulnerabilities in either engagement. None of that was wrong, and none of it was relevant, because the contracts executed correctly. The Trading contract accepted a signed price from an authorised reporter, and paid out against it, which is what it was audited to do.
The bug bounty is the sharper point. Ostium runs a programme on Immunefi with a ceiling of $200,000 for a critical smart contract finding, and its rules prohibit “any testing with pricing oracles or third-party smart contracts”. The path that took $23.75m was the path researchers were told to leave alone. That is a normal, defensible rule, written to stop bounty hunters spamming live price feeds, and this incident is the argument for pairing it with something else: a separate scope, a signed-report fuzzing environment, a testnet where the price plumbing is fair game. Arbitrum Sepolia already carries a full deployment, PrivatePriceUpKeep included.
The response has been fast and unusually specific by the standards of the category. Trading was frozen within 60 minutes of the first exploit transaction. Mandiant, zeroShadow, Collisionless and SEAL 911 are engaged alongside law enforcement, with exchanges, bridges and stablecoin issuers coordinating. The funds have not come back: the USDC was converted to roughly 12,080 ETH and about 10,540 ETH went into Tornado Cash within days, which is where recovery odds usually end.
A price display is not a balance sheet
The number an LP is shown is 1.1500. The number that determines what an LP can actually be paid is $13.4m against $34.3m of claims, and the difference between the two is a promise from Ostium Labs and its partners that has a shape but not yet a size.
Anyone underwriting a perpetuals vault should take one thing from this fortnight. Read the loss waterfall for what it excludes, not what it includes. Ostium’s is documented, honest and specific: subordination for trading losses, nothing for a security event, no insurance. That was true before 15 July, it is true now, and it is the most important sentence in the whole vault section.
Sources
- Ostium, "An update on where things stand" (19 July 2026)x.com
- Ostium, reopening and recovery-plan update (22 July 2026)x.com
- Ostium's founder, first account of the incident (15 July 2026)x.com
- Ostium documentation, Vault overview (buffer, senior tranche, UC state)docs.ostium.com
- Ostium documentation, OLP token and daily settlementdocs.ostium.com
- Ostium documentation, how the consensus oracle publishes pricesdocs.ostium.com
- Ostium documentation, managing positions (900% maximum take-profit)docs.ostium.com
- Ostium documentation, audits and mainnet contract addressesdocs.ostium.com
- Arbiscan, the largest exploit transaction (block 484,137,113)arbiscan.io
- Arbiscan, the Ostium Vault contractarbiscan.io
- Immunefi, Ostium bug bounty programme and prohibited testingimmunefi.com
- Coinbase Exchange, BTC-USD one-minute candles for 15 July 2026api.exchange.coinbase.com
- Ostium Labs press release, decentralised execution layer and protocol figures (28 April 2026)businesswire.com
- DefiLlama, Ostium total value lockeddefillama.com


