The year 2026 will be remembered as a difficult year for DeFi, due to numerous hacks. One of the main reasons, as I've written in other articles, is undoubtedly AI helping to find bugs. On July 15, 2026, the VLP vault at Ostium (Perps Exchange) was drained. This was a unique attack made possible by compromising the authorization keys used by the oracle for price feeds.
WHAT IS AN ORACLE?
The most famous oracle is Chainlink: it simply connects the on-chain world with the real world. Oracles are essential in DeFi, for example, for price feeds. Essentially, the oracle provides prices for opening/closing positions or for liquidations on lending platforms. If an oracle is manipulated/deceived, it can be made to "believe" something that isn't true (as happened on Ostium). In reality, the oracle wasn't tricked; one of its keys was simply compromised, and the attackers signed invalid transactions. It's crucial that these systems use networks of oracles, as just one isn't enough. A network of oracles that uses multiple confirmations is much more difficult to attack because they compare themselves with other oracles before validating.
PERPS EXCHANGE VAULT
In this case, the exchange vault was attacked. Many users believe these are simple vaults, where you deposit and earn an income. Nothing could be further from the truth. These vaults aren't stable, but their profitability is based on a simple concept:
"Most traders lose money".
Essentially, when you deposit into one of these vaults, you're acting as a "bank": you're exposed to traders' profits/losses. The vault's APR is derived from:
1) Traders' profits/losses.
2) Trade fees.
3) Liquidation fees.
4) Hacks or any other scam that disrupts the system.
Trading fees and liquidations are positive, as are trader losses. Profits, however, are negative. Overall, since most traders lose money, these vaults have APRs of up to 15, 20, or 30%.
HOW THE OSTIUM VAULT WAS DRAINED
Essentially, invalid transactions (trades) were signed with fake prices. The attackers compromised a valid authorization key used by the oracle and changed the opening and closing prices of the trades. Imagine this:
$BTC was priced at around $64,000.
This is how the attack happened:
1) Attacker deposited USDC to trade (as margin).
2) Opened a long trade on $BTC at $64,000.
3) He changed the opening price of the trade to $6,000 (as if he had bought $BTC at that price), signing the transaction as valid (after all, he was using a valid authorization key that the oracle trusted).
4) He closed the trade, setting the price of $BTC to 60,000 and signing with the key.
5) The trade opened at $6,000 and closed at $60,000. Huge profit in USDC, which was then withdrawn.
6) He repeated these operations many times until he withdrew $20,000,000.
7) Users exposed to the vault (exchange profits/losses) obviously suffered huge losses.

Keep in mind (if you're a newbie) that the price of the Bitcoin derivative was manipulated. This was not an attack on the Bitcoin network. The derivative on the exchange simply tracks the real price of $BTC. In general, this type of attack would have been avoidable if Ostium had used a network of oracles and not just one. The other oracles would have notified that the trade price was clearly fake.
Article always updated with all the possibilities of on-chain farming (airdrop): Some Sites To Earn Crypto Bonus (Old & New)