Cardano-based decentralized exchange Splash has patched the validator flaw behind a September 13 exploit, but OADA holders still do not have a reliable route to convert the token back into ADA. CryptoSlate reported Thursday that the attacker removed 2,434,648 ADA and 1,988,222 OADA from Splash’s ADA/OADA StableSwap pool. After subtracting the attacker’s 9,870 ADA deposit, the net ADA drain was about 2,424,778 ADA before network fees.
Splash’s incident analysis attributed the exploit to reserve accounting. The validator calculated a tradable ADA reserve after subtracting protocol fees, but failed to reject a negative result or enforce the direction of a swap. That allowed a transaction to pass validation after the effective reserve had fallen below zero.
The software fix addresses the cause described in the report. A patched validator is not recovered liquidity. The pool reportedly retained only about 10 ADA after the drain, leaving a large gap between OADA balances and the assets available for redemption or trading.
Why OADA holders remain trapped
Splash’s own public incident materials, as summarized by CryptoSlate, indicated that OADA did not have a protocol-level redemption mechanism. Other venues holding OADA were thin, which meant they could not absorb a large conversion even before accounting for slippage or arbitrage.
Optim Finance, which uses OADA in its products, paused related operations and removed remaining liquidity after the incident. Its September 15 update said the team was indexing the chain and compiling an accounting of affected addresses and assets, but did not announce restored liquidity, a redemption route or a compensation plan.
That creates a balance-sheet problem in addition to a code problem. Reopening a pool with fresh ADA could expose the new liquidity to discounted OADA inventory elsewhere, allowing arbitrageurs to capture the replenishment before existing holders receive a fair exit. A recovery plan therefore needs both technical controls and a transparent treatment of the missing assets.
What to watch next
The incident does not show that Cardano’s base layer or consensus was compromised. The evidence points to an application-level validator failure in one StableSwap pool. That distinction matters, but it does not reduce the practical impact for users who relied on the pool for liquidity.
The next useful disclosures are a complete postmortem, a list of affected contracts and addresses, independent review of the patch, and a concrete proposal for liquidity or redemption. Users should verify official domains and avoid anyone asking for seed phrases, private keys or upfront fees to recover OADA.
The pool’s future depends on governance, funding and user trust as much as on corrected code. The exploit patch does not close the loss. Until Splash or Optim Finance documents a verifiable recovery mechanism, OADA remains an impaired and highly speculative asset, and this report is not investment advice.