2,434,648.42 ADA and 1,988,222.18 OADA removed in the main drain; net ADA drain 2,424,778.42 ADA; OADA liquidity impaired.
The September 13 exploit hit Splash's OADA/ADA StableSwap. The main drain transaction removed 2,434,648.42 ADA and 1,988,222.18 OADA. After the attacker's 9,870 ADA input, the net ADA drain was 2,424,778.42 ADA.
Technical mechanism
Current incident reporting attributes the exploit to a validator reserve-calculation flaw. Tradable reserves were derived after subtracting accrued protocol fees, but the validator did not enforce a positive resulting reserve. The attacker manipulated the fee counter and drove the real ADA balance below it, allowing a negative reserve state to pass validation.
This was an application-layer failure, not a Cardano consensus compromise.
Secondary liquidity damage
The attacker moved stolen OADA into thin secondary markets. Reporting says roughly 115,000 ADA was realized from one OADA sale while about 1.76M OADA remained in a thin pool at a fraction of its intended peg. Optim Finance paused OADA-related operations.
Splash attributed 786,851 ADA to a KuCoin-linked deposit cluster and 550,000 ADA to Gate.io, with roughly 1.21M ADA in other custodial systems. These are tracing attributions, not evidence the exchanges participated.
Evidence Status
Confirmed / Project-reported + On-chain: quantities, validator flaw, pause and tracing. Developing: recovery, final LP loss, OADA peg restoration, compensation and attacker identity.
Risk Assessment
Critical.
What to Watch Next
CEX freezes, fund recovery, OADA liquidity restoration, Optim accounting, compensation and validator remediation.
FAQ
Is the event confirmed?
The core facts above are limited to the latest verified official, on-chain or reputable incident reporting.
Are community claims included as facts?
No. Community-only claims remain Community / Unverified.
Can the status change?
Yes. Recovery, exchange freezes, votes and liquidation execution can materially change the status.
Does an application exploit mean the base chain failed?
No. Application-layer and governance failures are separated from base-layer consensus.
What should be monitored next?
The event-specific recovery, execution, governance or compensation milestones listed above.