Splash confirmed on September 14 that a validator vulnerability drained its ADA/OADA StableSwap pool the previous day, leaving a net loss of about 2,424,778.42 ADA. The attacker used two transactions in less than a minute, while no other Splash pool types were affected, according to the protocol’s incident report.