Tonight's Tekin Night dissects the $23.75M off-chain heist at Ostium, the massive FakeGit malware campaign on GitHub, and Stellar Blade's uncensored arrival on Switch 2.
$23.7 Million Stolen from Ostium in Sophisticated Off-Chain Attack The crypto world was rocked tonight by news of another major exploit, but this one stands out for its novel attack vector. Ostium, a decentralized
trading platform, announced that attackers successfully drained $23.75 million from its liquidity provider vault. What makes this breach particularly concerning is that it targeted off-chain infrastructure
rather than smart contracts themselvesβa vulnerability that could affect many DeFi projects. Unlike typical DeFi exploits that target bugs in smart contract code, this attack compromised the off-chain
infrastructure responsible for feeding price data into the protocol. Ostium, like many trading platforms, relies on an oracle to provide real-time asset prices. This oracle is an external system that aggregates
price data from various exchanges and feeds it to smart contracts. [IMAGE_PLACEHOLDER_1] The attacker gained access to this off-chain system and was able to send falsified price reports that appeared completely
legitimate. Because these reports came from Ostium's authorized server and were signed with valid keys, the smart contracts accepted them without question. With manipulated prices in place, the attacker
could open trading positions with artificial profits and extract funds. The impact was immediate and severe. Ostium's Total Value Locked (TVL) plummeted from $32.7 million to just $9 millionβa staggering
72% drop. This indicates that users rapidly withdrew their funds from the platform, either out of fear of additional attacks or loss of confidence in the platform's security measures. Ostium has stated
Read Full Article