to leave a comment.

▲ Cardano (ADA), Hacking, Cryptocurrency Security/AI Generated Image
Splash, a decentralized exchange based on Cardano (ADA), suffered a security vulnerability attack, losing 2.42 million ADA and 1.98 million OADA.
According to The Crypto Basic on September 14 (local time), Splash reported that an attack occurred in the ADA/OADA stable swap pool between 00:47 and 00:48 on September 13. The attacker withdrew assets through two transactions. In the second transaction, 2,434,648.42 ADA and 1,988,222.18 OADA were withdrawn. Excluding the 9,870 ADA initially deposited by the attacker, the net outflow of ADA amounted to 2,424,778.42 ADA.
Splash explained that a vulnerability in the pool's validator was the cause of the attack. The validator calculated the available reserve by deducting accumulated protocol fees from the actual balance but did not verify if the calculation result was positive. The attacker manipulated the fee counter and then lowered the actual ADA balance below that figure. As the validator allowed negative reserves, the attacker was able to withdraw both ADA and OADA.
Optim Finance, a Cardano-based DeFi yield optimization platform, stated that the damage was limited to Splash pools supporting ADA and OADA. Some liquidity pools pairing OADA with other tokens were also affected, but no damage was confirmed in other types of pools. Immediately after the incident, Splash suspended the protocol and recovered related liquidity. Currently, there is no significant liquidity remaining in the affected pool to exchange OADA for ADA.
The attacker moved the stolen OADA to Minswap's low-liquidity OADA/FLDT pool and then swapped some for ADA. Due to insufficient liquidity, the actual ADA obtained was only approximately 115,000 ADA. As of the time of reporting, 1.76 million OADA remained in the Minswap pool. Splash warned against supplying new liquidity to the ADA/OADA pool, citing the risk of arbitrage using the remaining OADA.
Some of the stolen ADA's movement paths have also been confirmed. The attacker divided the funds into six deposit addresses and then consolidated them into four groups of custodial service accounts. Splash identified that 786,851 ADA was linked to KuCoin and 550,000 ADA to Gate.io. The operator of the custodial service holding the remaining 1.21 million ADA has not been identified. Splash contacted the two exchanges to continue tracking the funds and proposed a bug bounty or white-hat asset return negotiation to the attacker.
Prior to this incident, the Cardano ecosystem experienced a series of security breaches. Dano Finance lost 523,546 USDA, 457,808 USDM, 737,708 USDCx, and 7,131,442 NIGHT due to a loan pool attack. At Empowa, approximately 143,710 ADA and 48,219 NIGHT were unauthorizedly transferred from the project's treasury wallet, and SecondFi reported that over 16 million ADA were stolen from 374 user wallets last June.
[Article Key Summary]
-Splash suffered a loss of 2,424,778.42 ADA and 1,988,222.18 OADA (net) due to a vulnerability attack on its ADA/OADA pool.
-The attacker exploited a vulnerability in the validator's reserve calculation, and Splash proceeded to suspend the protocol and recover liquidity.
-Among the stolen funds, 786,851 ADA and 550,000 ADA were identified as having moved to KuCoin and Gate.io related accounts, respectively.
*Disclaimer: This article is for investment reference only, and we are not responsible for any investment losses based on it. The content should be interpreted for informational purposes only.*
Newsletter
Get key news delivered to your email every morning
to leave a comment.