Splash Patches Cardano Exploit, but 2.4M ADA Remains Missing from OADA Pool
AI مارکیٹ کا خلاصہ
Splash patched a validator flaw that enabled a Sept. 13 drain of ~2.4M ADA from an ADA/OADA StableSwap pool, but the fix does not restore lost liquidity. With OADA lacking protocol-level redemption and secondary pools reportedly thin, holders' exit routes remain impaired, while any new ADA liquidity could be arbitraged against discounted OADA inventory. Ongoing pauses and accounting highlight continued operational and liquidity overhang on Cardano DeFi.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
ADA/USDT+8.13%
AI تجزیاتی سمجھ · ADA/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Three days after Splash's Cardano-based ADA/OADA StableSwap pool was drained, OADA holders were still left without a practical way to exit the token. While the bug could be patched, the ADA liquidity that enabled redemptions had already been removed from the pool.
In its incident report, Splash said a single actor used two transactions on Sept. 13 to withdraw 2,434,648 ADA and 1,988,222 OADA. After netting out the attacker's 9,870 ADA deposit (excluding network fees), the ADA taken totaled 2,424,778.
Splash attributed the exploit to how the pool validator computed a "tradable" reserve: it subtracted accrued protocol fees from actual balances, but did not require the resulting reserve to stay positive. The validator also only bounded fee changes from below and did not enforce swap direction. These gaps allowed a transaction to be accepted after the tradable ADA reserve went negative.
Splash said the reconstructed attack would have been prevented by either a reserve-domain check or a two-sided fee bound. Either change closes the documented exploit path, but neither restores the ADA already removed.
Right after the drain, the pool reportedly held just 10 ADA and about 1.44 million OADA. Its tradable ADA reserve was negative, and the LP token balance was unchanged. The liquidity hit was especially significant because Splash's Sept. 13 snapshot indicated OADA had no protocol-level redemption route. Other OADA venues cited in the report were also nearly empty at the time, with listed pools holding only single- or double-digit ADA balances.
The attacker's subsequent OADA selling added another complication. At 14:53 UTC on Sept. 13, a Minswap V2 OADA/FLDT pool held 1,763,923 OADA against 45,751 FLDT. Splash warned that any new ADA/OADA liquidity could be arbitraged against that inventory, allowing discounted OADA to compete for fresh ADA if the pool reopened.
Splash concluded that a workable relaunch would require more than corrected validator logic. Restoring a functional exit for OADA holders would also require replenished ADA liquidity or a protocol redemption mechanism, plus a plan to manage the large OADA inventory sitting in a thin secondary market.
Optim Finance said on Sept. 13 that its protocol was paused, remaining liquidity had been removed, and OADA-to-ADA swaps were unavailable. In a Sept. 15 update, it said it was indexing the chain and compiling a full accounting of impacted addresses and assets while working toward a resolution. The update did not indicate that liquidity, redemption, or operations had been restored.