T
iTokenly

Splash (OADA/ADA stableswap) hack — September 2026

Verified — 2 sourcesLast checked September 19, 2026

Incident facts

Date of incident
Target typeDecentralised exchange
Loss$502,740Price at time of incident
MethodContract logic errorThe pool validator computed a tradable reserve by subtracting accrued fees from real balances, never required it to stay positive, bounded fee changes only from below and did not enforce the direction of a swap, so swaps kept executing after the tradable ADA reserve had gone negative
ChainsCardano
OutcomeUnresolved

What happened

An attacker emptied the OADA/ADA stableswap on Splash, a Cardano exchange, at 14:53 UTC on 13 September 2026, taking 2,434,648 ADA and 1,988,222 OADA in two transactions. Net of the 9,870 ADA the attacker had deposited, and before network fees, 2,424,778 ADA left the pool, about $503,000 at the CoinGecko price for that day.

The 1,988,222 OADA is deliberately not valued here. OADA is an ADA-pegged synthetic issued by Optim Finance, and the same actor went on to empty every other venue where OADA was paired, so there was no market left to sell it into at par. Converting it at ADA parity would state a price the attacker could not have realised.

Splash's incident report says the pool validator computed a tradable reserve by subtracting accrued protocol fees from its real balances, never required that reserve to stay positive, bounded fee changes only from below, and did not enforce the direction of a swap, so swaps kept executing once the tradable ADA reserve had gone negative. Splash has patched it and says a reserve-domain check or a two-sided fee bound would have stopped the reconstructed attack. Neither brings back the ADA.

The pool was left holding 10 ADA and about 1.44m OADA. OADA has no protocol-level redemption and this stableswap was the documented way out of it, so holders are left without an exit. Optim Finance paused its protocol on 13 September, withdrew the remaining liquidity and stopped OADA-to-ADA swaps; on 15 September it said it was indexing the chain to compile a full accounting of affected addresses and assets, without restoring liquidity, redemption or operations.

Sources

  1. CryptoSlateSecondary · retrieved 2026-09-19
  2. The Crypto TimesSecondary · retrieved 2026-09-19

Changes to this entry

  • Recorded six days after the incident. The 15 September sweep left it out because no amount had been published; Splash's incident report then gave the token counts. The amount is 2,424,778 ADA at the CoinGecko price for 13 September. The 1,988,222 OADA taken is not converted, because the attacker had drained OADA's remaining venues and there was no market to realise it at par.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Splash (OADA/ADA stableswap) hack — September 2026", iTokenly, accessed 2026-09-20, https://itokenly.com/hacks/splash-oada-stableswap
https://itokenly.com/hacks/splash-oada-stableswap

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.