MAINNETBETA
8.6HIGHcritical
Derivatives6 sectionsrun #1
Findings9 critical18 high3 medium
DEPGOVTKNAUDCTR
Last analyzed 12d ago runs

Summary

Ostium is an Arbitrum perpetuals exchange for synthetic real-world assets (forex, commodities, equities, crypto) with roughly $38M TVL remaining after a July 15, 2026 exploit drained an estimated $18M from the OLP liquidity vault. Trading is paused and overall risk is very high at 8.6/10, driven by a confirmed oracle/keeper flaw that accepted future-dated price reports, catastrophic LP impairment, and a trusted-forwarder security model that failed despite six audits. Governance is centralized through team-controlled multisigs behind an 18-hour timelock, with no governance token or on-chain DAO.

Trust Assumptions

Users must trust that registered keeper forwarders and Stork/Chainlink oracle signers will never submit malicious or compromised price reports, that the 2-of-8 Manager Safe will only pause trading in genuine emergencies, and that the 3-of-7 Governance and 4-of-8 Dev Safes will not abuse upgrade authority over nine core proxy contracts. LPs additionally rely on the advertised junior capital buffer absorbing trader wins first, on daily off-chain hedging by Jump and other market makers replenishing vault USDC, and on share-price accounting updating promptly at settlement—assumptions all broken or strained by the July 2026 incident.

What Could Go Wrong

A compromised or malicious registered forwarder can again submit cryptographically valid but fabricated oracle prices—opening positions at extreme lows and closing at extreme highs in a single transaction—to drain vault USDC before daily PnL rate limits bind, as happened when BTC was marked from $5,000 to ~$60,000 for an ~$18M payout. OLP depositors face continued impairment: on-chain USDC fell to ~$8.95M against a stale share price implying ~$34M NAV (~3.8× overstatement), the junior buffer is depleted, and no LP reimbursement plan exists. If trading resumes without hardened timestamp validation, price-deviation bounds, and independent re-audit of keeper contracts, residual ~$38M TVL and ~$317M open interest remain exposed to the same single-path oracle architecture with no fallback.

Recommendation

Do not re-engage with Ostium trading or new OLP deposits until the team publishes a formal post-mortem, deploys on-chain fixes (upper timestamp bounds, price sanity checks, forwarder revocation), and completes a fresh audit of PrivatePriceUpKeep and related settlement contracts. Existing LPs should treat displayed share price as unreliable until the next settlement reflects actual vault USDC and should assume 41–73% impairment with no announced compensation. Monitor for verified contract upgrades on Arbiscan, Immunefi/bounty scope changes covering malicious keeper scenarios, official loss accounting and recovery updates, and a credible trading-resume timeline with third-party fix verification before considering any renewed exposure.

Key Findings (30)

critical
Future-Dated Oracle Reports Accepted in PrivatePriceUpKeeporacle
critical
Registered Keeper Forwarders Fully Trusted for Price Settlementaccess-control
critical
July 2026 Exploit Imposed Catastrophic LP Impairmentlp-loss
critical
Junior Buffer Depleted — OLP Now Bears First-Loss Risksubordination-failure
critical
Stale OLP Share Price Overstates LP NAV by ~3.8× Post-Exploitshare-price
critical
Registered Keeper Forwarder Trust Failed — $18M Exploitkeeper
critical
No Upper Bound on Oracle Report Timestamporacle
critical
July 2026 exploit despite multiple auditspost-audit-exploit
critical
July 2026 Oracle/Keeper Exploit — ~$18M OLP Vault Drainincident
high
Six Core Proxy Addresses Unverified on Arbiscanverification
high
All Core Contracts Behind TransparentUpgradeableProxyupgradability
high
LockedDepositNft Completely Unverifiedverification
high
No On-Chain DAO — Multisig-Controlled Protocolcentralization
high
Instant Trading Pause Without Timelockcentralization
high
Keeper Registration Timelocked but Exploit Shows Trust Failurekeeper-trust
high
Extreme Open-Interest-to-Vault Leveragecounterparty-risk
high
Protocol Captures Majority of Opening Fees; LP Allocation Is Governance-Tunablefee-extraction
high
Async Withdrawals With Multi-Day Settlement Delay Create Exit Frictionwithdrawal-risk
high
All 75 Trading Pairs Route Through Private Ostium Verifier Pathoracle
high
Chainlink Data Streams Dependency for Crypto Keeper Pathoracle
high
Stork Network RWA Price Dependency via Authorized Signersoracle
high
Gelato and Automation Keeper Infrastructure Dependencykeeper
high
Off-Chain Hedging and Daily Settlement Counterparty Riskcounterparty
high
Six unverified contracts cannot be independently auditedaudit-gap
high
Exploit vector (PrivatePriceUpKeep keeper manipulation) outside effective audit threat modelscope-gap
high
Rapid Trading Pause but Incomplete Incident Responseresponse
high
Immunefi Scope Excluded Compromised Keeper Attack Pathbug-bounty
medium
OstiumVerifier Does Not Validate Report Timestamp or Price Boundsoracle
medium
Public PriceUpKeep Shares Same Timestamp Validation Gaporacle
medium
Trading Halted Post-Exploit (isPaused and isDone)operational

Analysis Sections

Ostium has no governance token or on-chain DAO. Control is centralized across three Gnosis Safes (Governance 3/7, Dev/Proposer 4/8, Manager 2/8) routed through an 18-hour OpenZeppelin timelock (OstiumTimelockOwner) that owns ProxyAdmin and the Registry. Core contract upgrades and keeper forwarder registration require timelock execution, but trading pause is instant via a 2/8 manager multisig. The July 2026 oracle/keeper exploit (~$18M) occurred while trading was governed by registered keepers treated as trusted actors.

Findings (7)

highNo On-Chain DAO — Multisig-Controlled Protocol

Ostium has no governance token or public voting. Protocol changes are executed by team-controlled Gnosis Safes: Governance Safe (3/7 at 0xdead60ad9900fb3bb81bd150c5f7954beb9712b5), Dev/Proposer Safe (4/8 at 0x1cd84f9b95d3fc7dbba5f7428fb17c4f2ee29e50), and Manager Safe (2/8 at 0xca73392e884c21fbf747b0cdca73f7d2e9b94a51). Registry storage slots verified on-chain.

on-chain RPCRegistry storage: owner=0xeb85dc... (Timelock), gov=0x733ef046 (GovGuard), dev=0x1cd84f9... (Safe 4/8), manager=0xca73392e (Safe 2/8)
discovery.jsonNo governance token; governanceType: timelock
highInstant Trading Pause Without Timelock

OstiumTrading.pause() is gated by onlyManager (registry.manager()), allowing the 2-of-8 Manager Safe to toggle trading pause immediately with no timelock delay. Trading was paused on 2026-07-15 following the exploit. This is appropriate for emergencies but grants substantial unilateral power to a low-threshold multisig.

contract source (Etherscan)function pause() external onlyManager { isPaused = !isPaused; }
on-chain RPCManager Safe 0xca73392e... threshold 2/8
discovery.jsontradingStatus: paused as of 2026-07-15
highKeeper Registration Timelocked but Exploit Shows Trust Failure

registerForwarder on PriceUpKeep, PrivatePriceUpKeep, and TradesUpKeep uses onlyTimelock (msg.sender must equal Registry owner = Timelock), requiring an 18-hour delayed timelock transaction. However, the July 2026 exploit used a registered PrivatePriceUpKeep forwarder to submit fabricated oracle prices and drain ~$18M from the OLP vault. unregisterForwarder uses onlyGov (OstiumGovGuard), callable by the 3/7 Governance Safe without timelock on the UpKeep contract itself.

contract source (Etherscan)registerForwarder(...) public onlyTimelock; unregisterForwarder(...) public onlyGov
discovery.json2026-07-15 exploit via OstiumPrivatePriceUpKeep fabricated prices, ~$18M loss
medium18-Hour Timelock on Upgrades and ProxyAdmin

ProxyAdmin (0x083F97BabF33D4abC03151B5DEc98170761f4025) owner is OstiumTimelockOwner (0xEb85DC6095c74D36500c9CdCacc15EcDC223BbF7), verified via owner() call. Timelock minDelay is 64,800 seconds (18 hours) per storage slot 2. All nine core proxies (Vault, Trading, TradingStorage, TradingCallbacks, PairInfos, PairsStorage, PriceUpKeep, PrivatePriceUpKeep, TradesUpKeep) point to this ProxyAdmin. Dev Safe holds PROPOSER, EXECUTOR, and CANCELLER roles on the timelock.

on-chain RPCProxyAdmin.owner() = 0xeb85dc6095c74d36500c9cdcacc15ecdc223bbf7; timelock storage[2] = 0xfd20 (64800 sec)
on-chain RPCEIP-1967 admin slot on Vault = 0x083f97babf33d4abc03151b5dec98170761f4025
on-chain RPCRoleGranted: PROPOSER/EXECUTOR/CANCELLER -> 0x1cd84f9b95d3fc7dbba5f7428fb17c4f2ee29e50
mediumOverlapping Signers Across Governance Multisigs

Multiple signer addresses appear on all three Safes (e.g., 0xac7935db..., 0x640ecde4..., 0x190628de..., 0xac40c7aa..., 0xb27f1880..., 0x25d83c56...). Compromise or collusion among a small subset could affect timelock proposals, GovGuard executions, and emergency pause simultaneously.

on-chain RPCGovernance Safe 3/7, Dev Safe 4/8, Manager Safe 2/8 — shared signers verified via getOwners()/getThreshold()
mediumOstiumGovGuard Mediates Registry Gov Role

Registry.gov is OstiumGovGuard (0x733ef046e1f1770e9f426def1bd08eca6e6d82dc), not a multisig directly. Constructor immutables: governance=0xdead60ad... (Governance Safe 3/7), timelock=0xeb85dc..., registry=0x799a13.... GovGuard.execute() routes Registry mutations through the timelock and other protocol calls through the Governance Safe.

contract source (Etherscan)OstiumGovGuard: if target==registry require timelock; else require governance Safe
on-chain RPCGovGuard creation bytecode args: registry, governance=0xdead60ad..., timelock=0xeb85dc...
infoSingle-Chain Deployment — No Cross-Chain Governance Gap

All production contracts are deployed on Arbitrum only. ProxyAdmin and TimelockOwner govern all discovered proxies on this chain; no L2-specific deployer EOA with divergent admin powers was identified.

discovery.jsonchains: [arbitrum], crossChain: false
on-chain RPCAll proxy admin slots resolve to 0x083f97babf33d4abc03151b5dec98170761f4025

Governance Checklist

Multisig (not EOA) controls adminThree Gnosis Safes: Governance 3/7, Dev 4/8, Manager 2/8
Timelock on contract upgrades18-hour delay via OstiumTimelockOwner owning ProxyAdmin
Timelock on keeper registrationregisterForwarder requires Timelock as caller (onlyTimelock)
On-chain token governance / DAONo governance token
Pause gated by timelockManager Safe 2/8 can pause instantly
Decentralized signer setOverlapping signers across all three Safes

Governance Entities

timelockarbitrumOstiumTimelockOwner
proxy-adminarbitrumProxyAdmin
multisigarbitrumGovernance Safe (GovGuard.governance)
multisigarbitrumDev/Proposer Safe (Registry.dev)
multisigarbitrumManager Safe (Registry.manager)
contractarbitrumOstiumGovGuard (Registry.gov)
registryarbitrumOstiumRegistry

Upgrade & Admin Control Flow

Loading graph…
Loading dependency graph…