Cardano Splash exploit drains 2.4M ADA; OADA holders trapped without redemption
In brief
- Attacker drained 2.4M ADA and 2M OADA from Splash's ADA/OADA pool via two Sept. 13 transactions
- Validator lacked reserve checks and fee bounds, enabling the exploit
- Post-patch pool holds only 10 ADA against 1.44M OADA with no redemption mechanism
- Optim Finance paused operations; no restoration timeline provided
The drain and its mechanics
One actor used two transactions on Sept. 13 to remove 2,434,648 ADA and 1,988,222 OADA from the Splash pool. After subtracting the attacker's 9,870 ADA deposit and before network fees, the net ADA drain totaled 2,424,778 ADA.
The root cause was straightforward: Splash's validator did not require the tradable reserve to remain positive, bounded fee changes only from below (not above), and did not enforce the direction of a swap. These omissions created a compounding vulnerability. A reserve-domain check or a two-sided fee bound would have stopped the reconstructed attack.
Immediately after the drain, the pool held 10 ADA and about 1.44 million OADA. The imbalance was catastrophic.
The liquidity crisis
The real trap for OADA holders isn't the patch—it's the ecosystem vacuum. According to Splash's September 13 snapshot, OADA had no protocol-level redemption. Other OADA venues listed in the report were close to empty at that time, with the listed pools holding only single- or double-digit ADA balances. At 14:53 UTC on Sept. 13, a Minswap V2 OADA/FLDT pool held 1,763,923 OADA against 45,751 FLDT, a thin pool with severe slippage risk for any meaningful exit.
A code patch can stop the documented exploit path, but restoring an OADA exit also requires ADA liquidity or redemption and management of the thin-pool OADA inventory. Without those, holders face a one-way market.
Response and outlook
Optim Finance paused its protocol on September 13, removed remaining liquidity, and made OADA-to-ADA swaps unavailable. In a Sept. 15 update, it said it was indexing the chain and compiling a full accounting of impacted addresses and assets while working toward a resolution. That update did not announce restored liquidity, redemption or operations.
The patch is defensive. The real work—restoring exit liquidity and enabling redemption—remains unresolved.


