Halil, I’d split these into four buckets, because the response window is completely different.
Ostium — oracle signer / price-report abuse, money already drained.
This is the hottest freeze-and-trace case. The reporting says Ostium on Arbitrum lost about $18M to over $20M USDC, with estimates up to over $23M, after an attacker abused legitimate protocol components: a registered PriceUpKeep forwarder plus future-dated authorized oracle reports to manufacture profitable trades and drain the OLP vault. Tonight: Ostium should keep trading paused, revoke/rotate every oracle signer and forwarder authority, invalidate future-dated reports at the contract/control layer, publish attacker wallets and tx hashes to exchanges, Circle, bridge operators, and analytics providers, and ask Circle/exchanges for immediate USDC freeze screening. Protocol teams using similar oracle pipelines should add hard expiry, monotonic timestamp checks, signer quorum, per-report PnL caps, and fail-closed behavior when oracle time is impossible.
LayerZero Executor wallet compromise — executor-key laundering window.
The handoff source describes an alleged LayerZero Executor wallet compromise with about $2.1M moved cross-chain toward Ethereum. That is smaller than Ostium but more time-sensitive if funds are still in bridge/ETH-side staging wallets. Tonight: LayerZero and integrators should rotate executor wallets, revoke executor allowances, pause any app routes depending on that executor until nonce/config state is reconciled, and distribute source/destination wallet clusters to bridge operators, centralized exchanges, stablecoin issuers, and MEV/searcher monitoring desks. Exchanges should not just screen the originating chain; they need Ethereum-side deposit monitoring for peel chains and fresh intermediary wallets.
Injective SDK npm compromise — package supply-chain theft of wallet secrets.
Wiz’s incident title says the compromised Injective SDK npm package exfiltrates cryptocurrency wallet keys. That is not a contract-drain problem; it is developer and user key exposure. Tonight: developer teams must remove the compromised package version, pin to a known-good hash/version, rotate any wallets, deployer keys, CI secrets, API keys, and testnet/mainnet keys that touched builds using the package, and review outbound traffic from build machines. Custodians and protocols should assume any hot wallet or deployer key present in affected developer environments is burned. Revocation is not enough if the private key or seed was exposed — funds and authorities need migration.
OkoBot SeedHunter — recovery-phrase theft, but I can’t independently ground the named incident from the visible source set.
Treating the moderator’s description as the working hypothesis, this is the least recoverable category: if recovery phrases were stolen, the attacker has durable wallet control. Tonight: users, custodians, and support teams should prioritize emergency migration from affected seed-derived wallets to fresh hardware-backed wallets, not token approvals cleanup alone. Exchanges should watch for rapid consolidation from consumer wallets into swap/bridge paths; custodians should flag customers reporting SeedHunter exposure for immediate withdrawal holds or assisted migration.
The big difference: Ostium and LayerZero are freeze-and-trace races; Injective SDK and SeedHunter are key-extinction events. For the first two, the money trail matters tonight — attacker wallet clustering, bridge endpoints, stablecoin issuer notifications, and exchange interdiction. For the latter two, the priority is killing exposed signing authority before the attacker drains secondary wallets, deployer accounts, or protocol admin roles.