Solido Cash Exploit Drains 293M SUPRA, Foundation Suffers Biggest Loss
Solido Cash Exploit Report Reveals Foundation Suffers Biggest Loss in $SUPRA Attack
The decentralized finance (DeFi) sector has once again been reminded of the risks associated with smart contract vulnerabilities after Solido Money released a comprehensive incident report detailing one of the largest exploits to hit the Supra blockchain ecosystem this year.
According to the official investigation, the majority of the funds stolen during the Solido Cash exploit did not come from ordinary users. Instead, approximately 90% of the losses were absorbed by the Solido Foundation itself, significantly reducing concerns that retail lenders and borrowers suffered direct financial damage.
The report also disclosed that roughly 220 million SUPRA tokens were transferred to a wallet believed to belong to a Gate exchange deposit address, creating the possibility that a substantial portion of the stolen assets could eventually be frozen or recovered if exchange operators cooperate with investigators.
| Source: X SolidoMoney |
The incident has become one of the largest security events involving the Supra ecosystem in 2026, highlighting how a single pricing error inside a lending protocol can rapidly evolve into losses worth hundreds of millions of tokens.
Solido Money Publishes Detailed Investigation
The newly released report provides a minute-by-minute breakdown of how the exploit unfolded on July 23, 2026.
Investigators concluded that the attacker exploited an error within Solido Cash's collateral valuation system rather than compromising the blockchain itself.
Unlike many previous DeFi hacks involving private key theft, governance attacks, or flash loan manipulation, this exploit centered on inaccurate asset pricing that allowed the attacker to mint synthetic assets backed by collateral that had been dramatically overvalued.
As a result, the attacker generated large amounts of CASH tokens before immediately exchanging them for SUPRA, draining liquidity from protocol pools within hours.
Two Coordinated Attack Waves
The report divides the exploit into two separate attack phases.
Wave One
The first attack occurred at approximately 18:21:35 UTC.
Rather than executing multiple independent transactions, the attacker completed the exploit through a sophisticated sequence inside one blockchain transaction.
The process included:
- Purchasing undervalued collateral
- Depositing the collateral into Solido Cash
- Minting newly created CASH tokens
- Selling the CASH-generated assets for SUPRA
This single transaction reportedly produced approximately 266.78 million SUPRA.
Because every action happened within one transaction, the exploit left very little opportunity for protocol operators to intervene before the damage had already occurred.
Second Wave Expanded the Theft
Roughly three hours later, the attacker returned.
Beginning around 21:12 UTC, five additional wallets repeated essentially the same strategy.
Instead of relying on one automated transaction, the second phase used several manually executed transactions spread across multiple wallets.
This second campaign generated another 26.93 million SUPRA, bringing total stolen funds to nearly 293.71 million SUPRA.
Combined, both attack waves also created approximately 809,051 CASH in newly minted protocol debt.
Investigators believe the attacker intentionally divided assets among several wallets before consolidating them later to complicate blockchain tracking efforts.
Timeline Shows Carefully Planned Operation
The report indicates the attacker prepared funding well before launching the exploit.
The first wallet reportedly received approximately 398,044 SUPRA from an address believed to be associated with a centralized cryptocurrency exchange.
After completing the exploit, assets moved through several intermediary wallets.
Each address served as a temporary holding account before forwarding tokens to another destination, a laundering technique commonly observed following major DeFi exploits.
Although investigators stopped short of identifying the exchange involved, blockchain analysis suggests many of the final transfers ended at wallets linked to Gate deposit infrastructure.
Root Cause Identified as Oracle Pricing Failure
According to Solido Money engineers, the vulnerability was not caused by malicious validators, flash loans, or smart contract reentrancy.
Instead, the exploit resulted from what the report describes as an oracle misassignment.
SOLID, which functioned as protocol backstop collateral, became associated with an outdated price feed.
When that oracle stopped updating correctly, the protocol automatically switched to fallback pricing logic.
Unfortunately, the fallback mechanism mistakenly used token quote values rather than actual market prices.
Because of this error, collateral appeared significantly more valuable than it truly was.
The inflated collateral value enabled the attacker to mint enormous amounts of CASH while posting assets worth only a fraction of the required collateral.
Investigators described the incident as a combination of two weaknesses:
- Incorrect oracle pricing assignment
- Insufficient protocol risk controls preventing abnormal collateral valuations
The report specifically states that the exploit was not caused by smart contract reentrancy, flash loan abuse, or deliberate market manipulation.
Foundation Absorbed Most Financial Damage
Perhaps the most significant finding in the report concerns who actually suffered losses.
According to Solido Money, approximately 90% of the stolen value belonged to the Solido Foundation rather than retail users.
This distinction has become important for community confidence.
Unlike several previous DeFi collapses where customer deposits disappeared, Solido says ordinary users largely avoided direct losses because the exploit targeted newly created borrowing positions instead of existing customer balances.
The foundation's reserves were designed to support protocol liquidity and system stability.
As those reserves backed the affected lending pools, they ultimately absorbed the majority of the exploit's financial impact.
Existing Users Remained Largely Protected
The incident report emphasizes that existing lenders and borrowers were not directly liquidated or drained.
Instead, the attacker opened entirely new borrowing positions using artificially inflated collateral values.
Throughout the exploit:
- Existing loan positions remained active.
- Depositor balances stayed intact.
- Liquidation mechanisms continued operating normally.
- Previously established collateral positions were unaffected.
However, liquidity providers supplying SUPRA to trading pools experienced indirect losses.
Freshly minted CASH entered the market and was immediately exchanged for SUPRA, removing valuable liquidity while leaving liquidity providers holding assets whose market value quickly deteriorated.
Solido Flow Escaped the Attack
The investigation also clarified that Solido Flow, another product within the Solido ecosystem, was never compromised.
Although the platform temporarily suspended Flow operations as a precautionary measure, engineers found no evidence that attackers accessed or exploited that protocol.
The pause was implemented solely to reduce risk while engineers investigated the broader incident.
Majority of Stolen Funds Already Traced
Blockchain investigators have successfully tracked much of the stolen cryptocurrency.
According to the report:
- Approximately 220 million SUPRA—roughly 75% of all stolen assets—were transferred to a wallet believed to belong to a Gate deposit address.
- Around 46.78 million SUPRA remains visible on-chain and has not yet been moved.
- Approximately 26.93 million SUPRA appears to have been transferred to another unidentified exchange.
Because most of the stolen tokens eventually reached centralized platforms, investigators believe there remains a realistic possibility of freezing at least part of the funds before they are withdrawn or laundered further.
Emergency Response Activated Within Hours
After detecting the exploit, Solido engineers responded rapidly.
Between approximately 23:05 UTC and 23:12 UTC, the protocol disabled every collateral listing used by Solido Cash.
This emergency shutdown immediately prevented attackers from repeating the exploit.
The development team also initiated communications with cryptocurrency exchanges believed to have received stolen assets.
According to the report, exchanges were asked to:
- Identify account owners
- Freeze suspicious deposits
- Preserve transaction records
- Cooperate with law enforcement if requested
The team continues monitoring blockchain activity while coordinating with external security researchers.
What This Means for DeFi Security
The Solido incident illustrates how even relatively simple pricing mistakes can become catastrophic inside decentralized lending markets.
Oracle systems remain among the most critical infrastructure components supporting decentralized finance.
When pricing data becomes inaccurate, lending protocols may incorrectly calculate collateral values, opening opportunities for attackers to borrow or mint assets beyond legitimate limits.
Security experts have increasingly urged DeFi protocols to introduce:
- Multiple independent oracle providers
- Stronger circuit breakers
- Maximum collateral valuation caps
- Real-time anomaly detection
- Automated protocol shutdown mechanisms
As decentralized finance grows, these safeguards are becoming increasingly important for protecting both users and protocol treasuries.
Recovery Efforts Continue
While investigators have successfully identified much of the stolen cryptocurrency, recovering digital assets remains uncertain.
Much depends on how quickly centralized exchanges respond to freeze requests before attackers move funds elsewhere.
If exchanges cooperate promptly, blockchain transparency may help investigators recover at least part of the stolen assets.
However, if attackers successfully withdraw or bridge the funds into privacy-focused networks, recovery efforts could become significantly more difficult.
For now, Solido Money maintains that customer deposits remain secure, although the protocol continues managing the debt created during the exploit.
Conclusion
The Solido Cash exploit has become one of the most significant DeFi security incidents involving the Supra ecosystem in 2026. According to the project's investigation, the attack stemmed from an oracle pricing failure that allowed an attacker to mint CASH tokens using vastly overvalued collateral before exchanging them for nearly 294 million SUPRA.
While the Solido Foundation absorbed almost 90% of the financial losses, existing users were largely protected from direct balance reductions, helping preserve confidence in the protocol's core lending system. With approximately three-quarters of the stolen assets already traced to suspected exchange deposit addresses, recovery efforts remain active as investigators work alongside centralized exchanges and blockchain security firms.
The incident serves as another reminder that even mature DeFi platforms must continuously strengthen oracle security, collateral risk management, and emergency response systems to protect against increasingly sophisticated attacks.
hoka.news – Not Just Crypto News. It’s Crypto Culture.
Writer: Barland Vex Crypto Market Analyst & Onchain Storyteller
Barland Vex is a veteran crypto writer who treats the chaos of digital markets as his playground. With a sharp instinct for reading Bitcoin's movements, DeFi waves, and the narratives that move millions of dollars in a matter of hours, Vex delivers analysis that's always one step ahead of the market itself.
From deep onchain reports to bold trend predictions, every piece is crafted to give readers one thing: an edge. Followed by traders, builders, and investors who refuse to miss a beat, Barland Vex is the name the market turns to when things start moving wild.
Crypto Market Analyst & Onchain Storyteller
Barland Vex is a veteran crypto writer who treats the chaos of digital markets as his playground. With a sharp instinct for reading Bitcoin's movements, DeFi waves, and the narratives that move millions of dollars in a matter of hours, Vex delivers analysis that's always one step ahead of the market itself.