Skip to main content
Ostium’s smart contracts have been audited by three independent security firms. All audits confirm no critical vulnerabilities in production code, and the contracts are fully verified onchain.

Audit Summaries

Zellic

Who: Zellic is a smart contract audit firm specializing in DeFi security reviews and vulnerability research. Audit Period: Conducted in Q3 2024 Scope: Comprehensive review of core trading, vault, and liquidation contracts including trading execution, position settlement, fee calculations, and oracle price handling. Key Findings: No critical vulnerabilities identified in the audited smart contracts. The review confirmed proper implementation of collateral management, fee accrual mechanics, and liquidation logic. Minor recommendations were addressed in subsequent contract updates. Zellic’s detailed report is available in the link below. Download Zellic Audit Report (PDF)

ThreeSigma

Who: ThreeSigma is an independent security research firm focused on DeFi protocol audits and risk analysis. Audit Period: Conducted in Q4 2024 Scope: Secondary audit of trading contracts, OLP vault mechanics, rollover fee calculations, and position closure logic. The review included static analysis and dynamic testing across all major execution paths. Key Findings: No critical or high-severity vulnerabilities were identified. ThreeSigma confirmed correct implementation of variable fee structures, proper handling of leverage constraints, and appropriate liquidation threshold enforcement. All recommendations have been addressed or are slated for future upgrades. Download ThreeSigma Audit Report (PDF)

Pashov (Two Reviews)

Who: Pashov is an independent auditor and researcher with expertise in perpetual instrument protocols and oracle-driven pricing mechanisms. Audit Period: First review in Q2 2024; second security review in Q3 2024 Scope: First review covered core trading and vault contracts. Second review focused on oracle integration, price verification, and updates to liquidation automation following mainnet deployment feedback. Key Findings: Both reviews confirmed no critical vulnerabilities. Pashov verified correct implementation of oracle price feeds (Chainlink and Stork), proper liquidation automation via Gelato Functions, and secure handling of collateral. Minor observations in the first review were resolved prior to mainnet deployment.
Ostium’s use of decentralized oracles and external automation services (Chainlink Automations, Gelato Functions) distributes critical functions across independent providers rather than relying on any single operator.
Download Pashov Security Review (PDF) Download Pashov Second Security Review (PDF)

Mainnet Contract Addresses (Arbitrum)

All contracts below are verified on Arbiscan and can be inspected at any time to confirm code integrity:
ContractAddressArbiscan Link
ProxyAdmin0x083F97BabF33D4abC03151B5DEc98170761f4025View
Registry0x799a139aE56e11F0476aCE2f6118CfcAed9608d2View
Vault0x20D419a8e12C45f88fDA7c5760bb6923Cee27F98View
LockedDepositNft0xb4f1123BE58f5d69E1cf565ED8756C7fcf31c8D3View
TradingStorage0xccd5891083a8acd2074690f65d3024e7d13d66e7View
PairInfos0x3890243a8fc091c626ed26c087a028b46bc9d66cView
PairsStorage0x260E349F643f12797fDc6f8c9d3df211D5577823View
Trading0x6D0bA1f9996DBD8885827e1b2e8f6593e7702411View
TradingCallbacks0x7720fC8c8680bF4a1Af99d44c6c265a74e9742a9View
OpenPnlFeed0xE607aC9FF58697c5978AfA1Fc1C5C437a6D1858cView
TradesUpKeep0x959Da1452238F71F17f7DA5dbA2e9c04FEf57324View
PriceRouter0x4B0C3c77D398912491f192d265b237C8d4441AD7View
PriceUpKeep0x52B2a78E12b09B66C6c8ce291D653D40bAb77f0cView
PrivatePriceUpKeep0xB71ec9eBD8145daCaCF6724363143cb5567A3d36View
Verifier0xcCF233920e8cc9415ecF503b992881d69b6c47AdView

Testnet Contract Addresses (Arbitrum Sepolia)

The following contracts are deployed on Arbitrum Sepolia for development and testing:
ContractAddressSepolia Explorer Link
Registry0xf86cff7679BA3E99d21255d774088E25FE0ec34aView
ProxyAdmin0xaB5583ebf187b926e48DeB9e9bb13418255c665CView
TimeLockOwner0xbc7B65D3Aa1C38B39AC63f131D5245C51b83acbcView
LockedDepositNft0xfFAd1f402030000C93152D38E384C202DD233445View
Vault0x2fbf52c8769c5da05afee7853b12775461cD04d2View
Trading0x2A9B9c988393f46a2537B0ff11E98c2C15a95afeView
TradingStorage0x0b9F5243B29938668c9Cfbd7557A389EC7Ef88b8View
PairInfos0xEF5D3fC8A4651B32D2DAB967E1D91a67eCfa953EView
PairsStorage0x81e252CCF6BB99202220FDc0c5788bBd9e2473D0View
TradingCallbacks0x83DC7c5dDeAD58f47230b70e6EF6bc44064BD814View
OpenPnlFeed0x27db8B73eC5cbaa17B4e7D3D3F07EBDb2eE3e154View
PriceRouter0x30DA14a620c9724C1Bb5d1f04049a29e2413d3aAView
PriceUpKeep0x297775475E875025F58789dD46A9E2dcFCB0a1e1View
PrivatePriceUpKeep0x5d3Af2Ab23a5F38c548151F507F6dded9979B328View
Verifier0x52C8c22BF47657C172e5D7a7FB2C1156916BAc46View
TradesUpKeep0x9404A01D0546907e0bDCD0545146cB9781416E4cView
MockUsdc0xe73B11Fb1e3eeEe8AF2a23079A4410Fe1B370548View
Gelato PairInfosManager0xad42c5da19b8d3f8c20847cb5a1a2deb502b5d46View

Security Practices

Ongoing Monitoring

All Ostium smart contracts are continuously monitored for anomalies in fund flows, liquidation execution, and oracle prices. Any unexpected behavior triggers immediate investigation and, if necessary, protocol safeguards.

Responsible Disclosure

If you discover a security vulnerability in Ostium’s smart contracts, please report it responsibly to security@ostium.io. Do not publicly disclose the vulnerability before giving the team time to investigate and remediate.
Do not attempt to exploit any vulnerability you discover. Responsible disclosure protects the entire community and may qualify you for a security reward.

Verifying Contract Code

All mainnet and testnet contracts are fully verified on Arbiscan and Arbitrum Sepolia Explorer. To verify a contract:
  1. Navigate to the contract address on Arbiscan (mainnet) or Sepolia Explorer (testnet)
  2. Click the “Code” tab
  3. Compare the displayed source code against the Ostium GitHub repository
  4. Confirm the compiler version and optimization settings match the audit reports
This ensures transparency and allows anyone to independently audit the deployed code.

FAQ

No. All three audit firms (Zellic, ThreeSigma, Pashov) confirmed no critical vulnerabilities in production code. Minor observations have been addressed or are planned for future upgrades. The protocol has been operating on mainnet without critical incidents.
All contracts are verified on Arbiscan. Navigate to any contract address listed above, click “Code,” and inspect the source. You can also clone the Ostium GitHub repository and compare the code directly.
Ostium Labs monitors the protocol continuously and maintains relationships with top security researchers. If a vulnerability is discovered post-audit, the team will assess severity and implement a remediation plan (contract upgrade, market freeze, or emergency measures) depending on risk level.
  • How Ostium Works — Two-layer architecture and the four core services that run the protocol.
  • Vault Overview — Onchain settlement layer and two-tranche structure underpinning trader collateral.
  • Markets — All 60 trading pairs with leverage caps, fees, and trading hours.