Blockchain security firm Blockaid was the first to flag the exploit on-chain, noting that the attacker began swapping the stolen USDC into ETH via Kyber shortly after the attack . The attack unfolded in three steps:
Loss estimates across sources range from $12 million to $22 million, with most reports pegging the figure at ~$18 million . Blockaid estimated roughly $18 million in losses, while CertiK placed the figure at about $22 million; both firms attributed the incident to a compromise of Ostium's oracle system .
The percentage depends on the baseline used, and sources give different figures:
The most commonly cited figure is roughly 35% of the protocol's $34+ million treasury/vault .
Ostium raised approximately $27.8 million from backers including General Catalyst and Jump Crypto . Other earlier funding rounds were also reported, but General Catalyst and Jump Crypto are the two named institutional investors in connection with this exploit .
The Ostium exploit is not a novel smart-contract vulnerability — it is a private-key credential theft used to manipulate a trusted price-feed mechanism. That places it squarely within the dominant 2026 attack pattern:
According to DeFiLlama data, blockchain projects have collectively lost approximately $16.69 billion through hacks and exploits over time, with around 40% of those losses resulting from private key compromises . On a cumulative basis, more than $17 billion has been stolen via 518 recorded private key incidents over ten years .
The bottom line: the Ostium exploit was a textbook case of attackers shifting from exploiting code to stealing keys, where a small number of key-compromise events cause a disproportionately large share of total losses . For DeFi protocols, auditing smart contracts is no longer enough — securing oracle signer keys and other privileged credentials has become the new front line.