Splash confirmed on September 14 that a validator vulnerability drained its ADA/OADA StableSwap pool the previous day, leaving a net loss of about 2,424,778.42 ADA. The attacker used two transactions in less than a minute, while no other Splash pool types were affected, according to the protocol’s incident report.
Two transactions drained the ADA/OADA StableSwap pool
The attacker used two transactions between 00:47:36 UTC and 00:48:21 UTC on September 13 to withdraw 2,434,648.42 ADA and 1,988,222.18 OADA from the ADA/OADA StableSwap pool, Splash said. After accounting for ADA deposited by the attacker, the net ADA drain was approximately 2,424,778.42 ADA. Splash’s report said the incident was confined to the ADA/OADA StableSwap pool and that no other Splash pool types were affected.
Protocol-fee counter manipulation drove the reserve negative
Splash said a flaw in the StableSwap validator let the attacker manipulate the protocol-fee counter, making the calculated tradable ADA reserve negative and permitting withdrawals of both ADA and OADA.
The route was confined to the ADA/OADA StableSwap pool, according to Splash’s incident report, and did not represent a broad loss across the exchange infrastructure; no other Splash pool types were affected.
Pause removes OADA’s meaningful ADA conversion route
Splash was paused and affected liquidity was removed following the incident, according to reporting based on updates from Splash and Optim Finance. The drained pool had served as OADA’s meaningful route for conversion into ADA, leaving that function unavailable through the pool after the exploit.