Ostium Rebuilds Trading Stack With Gateway Three Months After $23.75M Exploit
Key Takeaways
- •Ostium announced on October 1 that it is rebuilding its Arbitrum-based trading stack around Gateway, which it says offers faster execution, unified margin, and upgraded security infrastructure.
- •The announcement came approximately three months after a July attack drained $23.75 million from Ostium's liquidity vault, following an update to the OLP recovery plan that Ostium shared on September 30.
- •According to Galaxy Research, the attacker used an approved oracle signer key and a registered PriceUpKeep forwarder to submit properly signed price reports with falsified timestamps, moving the funds in eight transactions to a single wallet.
- •Galaxy Research argued the exploit demonstrates that attackers can target credentials and infrastructure even when smart contracts function as designed, and recommended stronger signer-key management, verifier redundancy, and admin timelocks instead of withdrawal throttles.
- •Industry data underscores the stakes: TRM Labs recorded 207 hacks totaling $972 million in the first half of 2026, while CoinMarketCap put cumulative RWA perpetuals volume at $3.16 trillion as of August 31.

Ostium, a perpetuals trading platform built on Arbitrum, an Ethereum layer-2 network, announced on October 1 that it is rebuilding its trading stack around Gateway. The company says the new system delivers faster execution, unified margin — a structure in which a trader's positions share a single collateral balance — and upgraded security infrastructure. The rollout comes roughly three months after an attacker drained $23.75 million from the platform's liquidity vault in July, placing pressure on Ostium to demonstrate that the flaws behind the breach have been.
What Ostium says Gateway changes
In a post on X on October 1, Ostium framed Gateway as more than a patch. According to the announcement, the platform will retain the institutional connectivity introduced earlier this year while overhauling its execution process and margin management.
Ostium's decentralized execution layer, as reported by Cryptopolitan in July, routes on-chain orders to off-chain institutional partners that assist with hedging. Marco Antonio Ribeiro, the company's co-founder and chief technology officer, has said the entire setup was engineered for latencies below 100 milliseconds.
The Gateway announcement followed an update Ostium shared on its OLP recovery plan on September 30, underscoring the connection between repaying the drained pool and reconstructing the broader trading stack.
How the attacker drained the vault
According to Galaxy Research, the hacker gained access to two trusted components of Ostium's system: an approved oracle signer key and a registered PriceUpKeep forwarder. Oracles are services that relay external market prices to on-chain contracts, and control of an authorized signing key effectively determines what price reports those contracts will accept. Armed with these, the attacker submitted a properly signed price report bearing a later timestamp, had it verified, and repeatedly opened and closed trades against the falsified price.
Galaxy noted that Ostium's verifier checked whether the signer was authorized to submit a transaction, but not whether the underlying price was valid. The $23.75 million was moved in eight separate transactions to a single crypto wallet, with the largest executed as an atomic series of repeated open-and-close cycles.
Why the fix is a trust problem, not a code problem
Galaxy argued the incident illustrates a broader issue: even when smart contracts function as designed, attackers can target the humans, credentials, and infrastructure connected to them.
"Throttling withdrawals introduces censorship risk directly at the application layer." — Galaxy Research
Rather than withdrawal throttles, Galaxy recommended stronger signer-key management, verifier redundancy, and admin timelocks.
The pattern is visible in industry-wide data. TRM Labs recorded 207 hacking incidents in the first half of 2026, with losses totaling $972 million. Infrastructure and operational breaches accounted for only about 15% of incidents but roughly 76% of the losses.
A security test for a $3 trillion market
Research from CoinMarketCap put the cumulative volume of real-world asset (RWA) perpetuals — perpetual futures that track off-chain assets such as stocks — at $3.16 trillion as of August 31. August alone generated $799.5 billion of that total, with stocks responsible for 62.3% of the volume.
As of October 1, DefiLlama's RWA perpetuals dashboard showed open interest of $5.34 billion across 1,037 markets. The dashboard tallies RWA perpetuals by default, excluding centralized-exchange RWA perpetuals. CoinMarketCap has also found that centralized exchanges have begun capturing a larger share of RWA perpetual trading activity.
That landscape sets a clear benchmark for Gateway: deliver the speed and capital efficiency traders require, while ensuring the technology behind the platform is not easily breached. Against that backdrop, the details worth watching are how closely Gateway's new security infrastructure matches the safeguards Galaxy outlined, and how far the OLP recovery plan Ostium updated on September 30 has progressed toward repaying the drained pool.