Ostium rebuilds trading stack with Gateway after $23.75M exploit

- Ostium announced on October 1 that it is rebuilding its trading stack around Gateway, promising faster execution, unified margin and built-in security.
- This comes after an attacker drained $23.75 million from its OLP vault in July using legitimate oracle-signer and forwarder credentials.
- The move tests whether decentralized RWA-perpetual venues can combine institutional-style execution with infrastructure that holds up as the market scales past $3 trillion in cumulative volume.
Ostium announced on October 1 that it is revamping its trading setup using Gateway, a new system that offers greater speed of execution, a unified margin, and security features in its infrastructure.
This system is introduced about three months after the theft of $23.75 million from its liquidity vault, putting pressure on the Arbitrum platform to demonstrate that it has fixed the flaws that resulted in the breach in July.
What Ostium says Gateway changes
In a post on X on October 1, Ostium framed Gateway as more than just a patch. The platform says it will keep the institutional connectivity introduced earlier this year and will improve the execution process and margin management.
In July, Cryptopolitan reported that Ostium’s decentralized execution layer facilitated the process of sending on-chain orders to institutional partners off-chain to help with hedging. According to Marco Antonio Ribeiro—the co-founder and CTO of the company—the entire setup has been designed for latencies of under 100 milliseconds.
The announcement about Gateway came after Ostium shared an update on its OLP recovery plan on September 30—which illustrated the connection between repayment of the drained pool and rebuilding of the entire trading stack.
How the attacker drained the vault
According to Galaxy Research, the hacker managed to gain access to two trusted components of Ostium’s system – an approved oracle signer key and a registered PriceUpKeep forwarder. With the two, the hacker was able to submit a properly signed price report bearing a later timestamp, have it verified, and repeatedly open and close trades against that false price.
According to Galaxy, the verifier for Ostium checked if the signatory had the authorization for the transaction but not whether the price was valid. The $23.75 million amount was transferred in eight separate transactions to a single crypto wallet; the biggest transaction was carried out as an atomic series of repeated open-and-close cycles.
Why the fix is a trust problem, not a code problem
According to Galaxy, the case of Ostium illustrates a bigger issue: even if the smart contracts function properly, criminals can still target humans, credentials, and infrastructure connected to the smart contracts.
“Throttling withdrawals introduces censorship risk directly at the application layer.”— Galaxy Research
Instead, Galaxy argued for stronger signer-key management, verifier redundancy and admin timelocks.
This issue is illustrated by the TRM Labs data for the first half of 2026, in which there were 207 hacking incidents and losses amounting to $972 million. Although infrastructure and operational breaches only made up around 15% of the incidents, they were responsible for approximately 76% of the losses.
A security test for a $3 trillion market
According to research from CoinMarketCap, the total volume of real-world asset (RWA) perpetuals was recorded at $3.16 trillion as of August 31. Among them, August accounted for $799.5 billion of the total volume, with stocks responsible for 62.3% of the volume.

As of the first of October, DefiLlama’s RWA perpetuals dashboard indicated that open interest was $5.34 billion across 1,037 markets. The dashboard shows a total of RWA perpetuals, excluding centralized-exchange RWA perpetuals by default.
CoinMarketCap has also discovered that centralized exchanges have begun to acquire a bigger market share in RWA perpetual trading activities. Thus, Ostium now has a clear challenge for Gateway – to provide traders with the requisite speed and capital efficiency, while at the same time ensuring that the technology behind this platform cannot be breached easily.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
How much did Ostium lose in the exploit?
Galaxy Research estimated the attacker took $23.75 million in USDC from Ostium's OLP vault across eight transactions sent to a single wallet. Cryptopolitan's earlier coverage noted security firms' first estimates ranged from about $18 million to $20 million.
How did the attacker drain Ostium's vault?
According to Galaxy, the attacker held both an authorized oracle-signer key and a registered PriceUpKeep forwarder, then submitted a correctly signed, future-dated price report and repeatedly opened and closed positions against it to book fake profits. The verifier checked that the signer was approved but not whether the price was accurate.
How large is the RWA perpetuals market?
CoinMarketCap research put cumulative volume for perpetual futures on stocks, commodities, FX, and indices at $3.16 trillion through August 31, 2026, with August alone reaching a record $799.5 billion and stocks accounting for 62.3% of that month's volume
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Ibiam Wayas
Ibiam Wayas has covered the crypto news beat since 2019. He studied Computer Science at National Open University of Nigeria. His work has appeared on various crypto news platforms, including Coinfomania, Crypto News Australia, and AltcoinBuzz. Drawing on his background in Computer Science, he now focuses on crypto, robotics, and longevity news.
















