Ostium Hacker Launders 10,540 ETH Through Tornado Cash After $24M Arbitrum Vault Exploit
The Ostium OLP vault exploiter has routed 10,540 of 12,080 stolen ETH through Tornado Cash after a $24M Arbitrum hack revised up from $18M, per PeckShield.
The attacker behind the Ostium OLP vault exploit has routed 10,540 EETH$1,902.79▲1.98% through Tornado Cash, laundering the bulk of roughly 12,080 ETH stolen in a July 16 hack that blockchain security firm PeckShield now says cost the Arbitrum perpetuals protocol approximately $24 million in UUSDC$0.9998▲0.00% — well above initial estimates of up to $18 million.
PeckShield, which first flagged the exploit, revised the loss figure upward after on-chain tracking revealed the full scope of the drain from Ostium’s public OLP (Ostium Liquidity Provider) vault, according to BingX. The attacker swapped the stolen USDC for approximately 12,080 ETH, then began feeding the proceeds into Tornado Cash — the privacy mixer that severs the on-chain LLINK$8.56▲2.33% between deposit and withdrawal addresses.
Of that 12,080 ETH, 10,540 has already passed through Tornado Cash, according to The Defiant. That leaves roughly 1,540 ETH — about $2.9 million at current prices — still sitting outside the mixer.
At ETH’s current price of $1,876, the 10,540 ETH already laundered is worth approximately $19.8 million. The full 12,080 ETH haul comes to roughly $22.7 million. The gap between that figure and the $24 million USDC loss reflects swap slippage and price movement between the moment of the hack and now.
Ostium runs as a decentralized perpetuals trading protocol on Arbitrum. Its OLP vault is the protocol’s liquidity pool — the direct counterparty to every trade on the platform. Draining it doesn’t just hurt liquidity providers. It hollows out the protocol’s ability to back open positions entirely, leaving traders exposed with no counterparty behind them.
Tornado Cash has been sanctioned by the U.S. Treasury’s Office of Foreign Assets Control since 2022 and remains the crypto ecosystem’s most scrutinized mixing service. The mechanics are simple: deposit ETH, receive a cryptographic proof, withdraw later to a fresh address with no visible on-chain trail back to the original deposit. For anyone looking to move stolen stablecoins into untraceable ETH, it is the standard first stop. MyCryptoParadise and KuCoin both reported the deposits, citing PeckShield’s on-chain monitoring.
PeckShield Alert tracked both the initial exploit and the subsequent laundering movements. The revised $24 million figure places the Ostium hack among the larger DeFi exploits of mid-2026 — a stretch that has seen a steady run of protocol drains across Ethereum Layer 2 networks, even as auditing standards have tightened and real-time monitoring infrastructure has expanded.
The broader market backdrop is grim. The Fear & Greed Index sits at 29 out of 100, firmly in Fear territory, with total crypto market capitalization at $2,297.07 billion and ETH dominance at 9.9%. ETH itself is up 0.68% over 24 hours to $1,876, recovering 3.85% over the past week. A hack concentrated inside one protocol’s liquidity pool doesn’t move those macro needles much. The damage is Ostium’s problem, not the market’s.
The number to watch now is that remaining 1,540 ETH. Attackers typically move leftover funds in tranches — smaller batches spread across time to avoid triggering automated flags from on-chain monitoring tools. Whether PeckShield or competing firms can tag those wallets before the rest disappears into the mixer will determine how much of this hack is ever traceable, let alone recoverable.
Ostium has not publicly detailed a remediation plan or any reimbursement mechanism for affected liquidity providers.