Solido Money Exploit Drains 293.7M SUPRA, Worth $900K

3–4 minutes

Last Updated:

July 28, 2026

Fact checked by

Hooded hacker beside a glowing Supra logo in a dark cyber-themed setting, representing the Solido Money exploit.

Solido Money Exploit Drains 293.7M SUPRA, Worth $900K

Hooded hacker beside a glowing Supra logo in a dark cyber-themed setting, representing the Solido Money exploit.

Solido Money Exploit Drains 293.7M SUPRA, Worth $900K

Solido Money confirmed an oracle pricing exploit drained 293.7 million SUPRA tokens, worth roughly $900,000, across two separate attack waves. The protocol detailed the incident in a forensic report, tracing around 220 million SUPRA, nearly 90% of the stolen funds, to a suspected Gate.io deposit address. Solido’s chain now holds just $950,000 in total value locked, and its token is down 94% over the past year, a decline that leaves little room to absorb a loss of this size.

image1 45

Source – Solido Cash Incident | Consolidated On-Chain Forensic Report

How the Oracle Misassignment Enabled the Theft

Solido’s report traced the exploit to a single oracle misassignment. The flaw let the protocol price certain collateral at close to one U.S. dollar, even though its real market value sat at a fraction of that. Attackers used the mispriced collateral to mint CASH, Solido’s stablecoin, then sold it for SUPRA.

The first wave ran through one atomic transaction. The second wave, carried out several hours later, repeated the same method manually across five separate wallets, according to Solido. Combined, the two waves minted 809,052 CASH and generated net proceeds of 293.7 million SUPRA.

Solido traced about 246.9 million SUPRA, roughly 84% of the total proceeds, to centralized exchange infrastructure. The remaining 46.8 million SUPRA stayed on-chain at the time the report was published.

For the first wave, the report pointed to a suspected Gate.io deposit address holding 220 million SUPRA. Solido stressed that exchange ownership cannot be confirmed from on-chain data alone.

For the second wave, the report traced funds to a separate address it described as customer-specific exchange infrastructure, before the funds were swept into a shared omnibus wallet. Solido cautioned that both traces come from reading wallet behavior on-chain, not from confirmed identities, and that its report does not accuse either exchange of facilitating the attack.

What This Means for SUPRA Holders

Solido’s exploit adds to a run of DeFi protocols losing funds to oracle failures rather than smart contract bugs. An oracle is the price feed a protocol relies on to know what collateral is actually worth, and when it misreads that price, as Solido’s did, the protocol can let attackers borrow or mint far more than the collateral justifies.

If you’re still getting familiar with how DeFi lending platforms price and secure collateral, this exploit is a good example to learn from. Check how a project sources its price feeds before depositing funds, since that’s exactly where Solido’s setup failed. The risk is greater on a smaller chain like Solido’s, where $950,000 in TVL (Total Value Locked) leaves little room to absorb another hit like this one.

It’s also not an isolated case. We covered a similar-sized DeFi exploit at Kelp DAO earlier this year, where attackers moved a comparable volume of stolen assets through cross-chain infrastructure.

What Happens Next to the Traced 293.7M SUPRA

Solido said in its report that it has asked exchanges to help preserve and recover the traced proceeds, without naming Gate.io directly. That kind of recovery typically depends on an exchange freezing the flagged deposit addresses and using its own KYC records to identify the account holder, a step Solido cannot take on its own since blockchain data alone does not reveal real-world identities. Cooperation like that has worked before. Arbitrum froze 71 million in stolen Kelp funds earlier this year after a similar tracing effort.

Whether Gate.io or other platforms confirm and freeze the flagged wallets in the days following the July 23 report will determine how much of the 293.7 million SUPRA the Supra Foundation, which owned close to 90% of the stolen funds, can recover.

This article is for informational purposes only and does not constitute financial advice. Do your own research before making any investment decisions.

What this means for you: If you hold or use SUPRA, this exploit is a reminder that a protocol does not need a hacked smart contract to lose money. A wrong price reading was enough here, so before you deposit funds anywhere, check whether the project explains where its price data comes from and how it protects that feed from being manipulated.

Join our growing community

David Constantino

Author

David is a crypto enthusiast, airdrop farmer, and blog writer with a focus on discovering and analyzing new token launches and blockchain projects. He explores the latest trends, shares actionable insights, and guides readers through opportunities in the fast-paced world of digital assets.