Key Takeaways
- Solido Money released comprehensive forensic analysis following an exploit that resulted in the theft of roughly 293.7 million SUPRA tokens
- The attack unfolded in two distinct waves, both exploiting an oracle configuration error that dramatically inflated collateral valuations
- Blockchain tracking identified approximately 246.9 million SUPRA (84% of stolen funds) moving through centralized exchange systems
- Forensic evidence points to roughly 220 million SUPRA being sent to what appears to be a Gate.io deposit wallet
- The protocol has requested exchanges implement holds on identified deposits and retain account information for possible legal proceedings
Following a significant security breach on July 23, 2026, Solido Money has made public an extensive forensic investigation that maps the movement of compromised assets and appeals to centralized platforms for assistance in fund recovery.
According to the protocol’s findings, attackers executed two distinct exploit operations that collectively generated approximately 293.7 million SUPRA in illicit gains. Each operation leveraged an identical security weakness ā a misconfigured oracle that resulted in extreme overvaluation of deposited collateral.
This technical flaw caused Solido’s system to assess collateral value at approximately one U.S. dollar per unit, while the genuine market value represented only a small fraction of that amount. Exploiters capitalized on this artificially inflated valuation to generate CASH tokens, subsequently converting them to SUPRA.
The initial attack occurred through a single atomic blockchain transaction. Hours afterward, a second exploitation phase replicated the identical methodology manually using five different wallets.
Across both operations, attackers generated 809,052 CASH tokens and extracted 293.7 million SUPRA in total proceeds. Blockchain security provider PeckShield verified the incident and indicated that approximately 90% of the compromised assets belonged to the Solido foundation itself.
Fund Movement Analysis
Through on-chain forensic investigation, Solido determined that roughly 246.9 million SUPRA ā representing 84% of total stolen assets ā made its way to infrastructure associated with centralized cryptocurrency exchanges.
The balance of approximately 46.8 million SUPRA remained in on-chain addresses when the forensic report went public.
Regarding the initial attack wave, Solido’s analysis traced 220 million SUPRA to an address believed to be associated with Gate.io deposits. The team emphasized that blockchain evidence alone cannot definitively confirm this connection and requires direct exchange verification.
An additional exchange connection point was discovered relating to the subsequent exploit wave. These funds moved into what Solido characterized as customer-designated exchange infrastructure before consolidation into a collective omnibus wallet.
Solido’s Request to Exchanges
Solido has formally requested that cryptocurrency exchanges verify ownership of the identified wallet addresses. Additionally, the protocol seeks temporary freezes on deposits traced through their investigation and preservation of associated account documentation for potential law enforcement cooperation.
The team emphasized that their request does not involve freezing unrelated customer accounts indiscriminately and explicitly stated they are not suggesting any exchange participated knowingly in the attack.
In response to the security breach, Solido has implemented smart contract modifications that permanently disable the token minting pathway exploited in the attack. The report acknowledged that merely disabling their web interface proved insufficient to prevent the second wave of exploitation.
Solido clarified that their investigation relies exclusively on blockchain transaction evidence and does not identify any specific individuals behind the attack.


