Splash Pool Hacked: 242 Million ADA Drained Through Smart Contract Exploit
A security breach occurred on September 13th in the Splash pool that supported OADA, a stablecoin pegged to ADA. The hacker exploited a vulnerability in the smart contract used for ADA/OADA StableSwap pools.
The hacker executed two transactions, draining 243 million ADA and 198 million OADA from the pool. However, the hacker had previously deposited 9,870 ADA into the pool, so the actual amount stolen was approximately 242 million ADA.
An investigation by Splash revealed that the cause of the breach was a weakness in the validator smart contract. The contract did not properly check for conditions before allowing transactions to proceed.
The hacker used this vulnerability to drain the funds from the pool, and then exchanged some of the OADA for FLDT on the Minswap DEX. They later exchanged the FLDT for ADA, netting a total of approximately 115,000 ADA.