Ostium plans to resume trading this week, roughly five days after an attacker drained its liquidity vault, the Arbitrum-based exchange said on Monday, July 20. Traders and liquidity providers have had funds frozen since July 15, and the restart will be their first chance to act on positions in nearly a week.

The company stated that it would give at least 24 hours’ notice before trading reopens and that auditors, outside cybersecurity experts, and its own engineers were running final checks first.

When the platform comes back online, existing positions will be reopened at the price prevailing at restart.

Ostium runs a decentralized perpetuals venue on Arbitrum, letting users take leveraged bets on forex, commodities, metals, equities, and crypto from a self-custody wallet, with trades settled in $USDC. It closed a $20 million Series A in December 2025 co-led by General Catalyst and Jump, per DefiLlama.

What was taken during the Ostium exploit and what wasn’t

Ostium put the loss at 23,752,746 $USDC in a July 19 post on X, its most precise figure to date. The theft hit the Ostium Liquidity Pool, the vault where liquidity providers deposit $USDC to back trader positions and settle profit and loss.

In a follow-up post that was made after it confirmed the exploit, Ostium stated that “user positions remain open and unmodifiable, and trader margin remains unmoved in frozen trading smart contracts.”

Initially, there was no general consensus on the reporting around the estimated loss. Security firm Blockaid reported the loss to be around $18 million. Another reporting put it at $20 million, while Ostium’s own accounting and a review by Galaxy Research both landed at $23.75 million.

A signer key, not a smart-contract bug

According to Galaxy, the attacker held two legitimate credentials that are meant to be handed out only by Ostium governance: an authorized oracle-signer key and a registered PriceUpKeep forwarder, the role that fulfills pending orders.

Ostium’s verifier checks that a price report is signed by an approved signer, but not whether the price is real. With both credentials in hand, the attacker fed the system a correctly signed, future-dated price and traded against it.

Security firm Halborn described the mechanics in detail, stating that the attacker opened a Bitcoin position at a fabricated price of $5,000, then closed it at the real market rate near $60,000, pocketing the gap.

Halborn estimated the scheme generated around 900% profit per round across ten iterations. The security firm also noted that the targeted PriceUpKeep infrastructure had been left out of Ostium’s bug bounty scope, reducing the odds that a researcher would have flagged it first.

After the drain, the stolen $USDC did not stay put. PeckShieldAlert reported that the exploiter swapped it for 12,080 $ETH and sent 10,540 $ETH to the mixer Tornado Cash.

Ostium first told its community about the incident on July 16, saying only that trading was paused and authorities had been notified. The company has promised a technical post-mortem in the coming days.

What it has not yet detailed is how liquidity providers, who absorbed the full hit, will be made whole. It said it is still working out a path forward for them.