Cardano Pool Exploited for $4 Million in ADA and OADA
The Cardano (ADA) StableSwap pool operated by Splash was hit with a significant exploit on September 13, resulting in the removal of approximately 2.42 million ADA and nearly 1.99 million OADA.
The attack occurred due to missing reserve checks that allowed the validator to accept an invalid swap, according to BSCN. The incident left the pool with only 10 ADA and about 1.44 million OADA.
Splash has since patched the validator vulnerability, closing the documented exploit path. However, the patch does not restore the cryptocurrency drained during the attack, leaving OADA holders facing a separate liquidity problem.
The imbalance has direct consequences for OADA holders as the available ADA liquidity is insufficient to provide a meaningful exit through the affected pool. Other OADA liquidity venues were reported to have limited ADA reserves, further restricting available routes for holders seeking to exchange the token.