Cardano's Splash fix patches exploit but leaves OADA holders without a clear exit
Code patch addresses exploit but not the liquidity gap
Three days after a security exploit drained a major Cardano-based trading pool, Splash Protocol has confirmed a validator fix is available to stop the attack. However, the code update does not solve the broader problem: OADA holders currently lack a practical way to exchange their tokens back into ADA, the native currency of the Cardano network (a blockchain platform similar to Ethereum).
The exploit removed significant liquidity from the system, leaving a critical gap that a simple code correction cannot fill on its own.
Numbers and impact of the incident
- On September 13, a single actor used two transactions to remove 2.4 million ADA and nearly 2 million OADA from the pool.
- The drained pool subsequently held just 10 ADA, meaning OADA owners had no meaningful liquidity to trade into.
- Secondary trading pools for OADA were nearly empty at the time, with some holding only single- or double-digit ADA amounts.
What the official incident report says
Splash Protocol’s report identified a specific flaw in the pool’s validator code. The system calculated a tradable reserve by subtracting protocol fees from real balances but failed to require that this reserve stay positive or to limit the direction of a swap. This missing check allowed an attacker to push the tradable ADA reserve into negative territory and drain the assets. The new validator update enforces these reserve-domain checks and two-sided fee bounds, which according to Splash, would have blocked the reconstructed attack.
Why a relaunch requires more than code
While the new code patch closes the specific exploit path, it does not recover the ADA that was already extracted. A usable relaunch of the OADA pool would require replenished ADA liquidity or a protocol-level redemption mechanism. Additionally, a large inventory of OADA remains in a separate Minswap V2 pool. Splash noted that new OADA/ADA liquidity could be arbitraged against this existing inventory, meaning anyone could use discounted OADA to compete for any fresh ADA placed into a reopened pool.
What is still unclear
It remains uncertain when or how the missing ADA will be restored. Optim Finance, another protocol affected by the exploit, paused its services on September 13 and removed its remaining liquidity. As of September 15, Optim Finance stated it was working on a full accounting of impacted addresses but had not yet announced a path to restore liquidity, a redemption method, or resume operations.