TLDR
- Solido Money published a forensic report on a recent hack that drained approximately 293.7 million SUPRA from the protocol
- Two separate exploit waves both targeted an oracle misassignment flaw that caused collateral to be massively overvalued
- Around 84%, or 246.9 million SUPRA, has been traced to centralized exchange infrastructure
- Approximately 220 million SUPRA was traced to a suspected Gate.io deposit address
- Solido is asking exchanges to freeze traced funds and preserve account records for potential law enforcement
Solido Money has released a detailed forensic report following a hack that took place on July 23, 2026. The report traces the flow of stolen funds and asks centralized exchanges for help recovering them.
⚠️ALERT: Solido reports an exploit drained 293.7M $SUPRA worth $900K.
Around 220M $SUPRA has reportedly been routed to a suspected Gate deposit address, with nearly 90% of the stolen funds believed to have belonged to the Supra Foundation.
The chain now holds just $950K in TVL… pic.twitter.com/147zAlvGeM
— Coin Bureau (@coinbureau) July 28, 2026
The protocol said two separate exploit waves generated a combined 293.7 million SUPRA in net proceeds. Both waves exploited the same vulnerability — an oracle misassignment that caused the protocol to massively overvalue collateral.
The flaw made the system believe collateral was worth nearly one U.S. dollar, when its actual market price was only a fraction of that. The attacker used this mispriced collateral to mint CASH tokens, which were then sold for SUPRA.
The first wave was executed in a single atomic transaction. The second wave repeated the same method manually across five separate wallets, several hours later.
Together, the two waves minted 809,052 CASH tokens and produced 293.7 million SUPRA in net proceeds. PeckShield, the blockchain security firm, confirmed the attack and noted that roughly 90% of the affected funds belong to the Solido foundation.
Where the Funds Went
Solido’s on-chain analysis found that approximately 246.9 million SUPRA — about 84% of the total stolen — reached centralized exchange infrastructure.
The remaining 46.8 million SUPRA was still sitting on-chain at the time the report was published.
For the first wave, Solido said 220 million SUPRA was traced to a suspected Gate.io deposit address. The company noted this could not be confirmed from blockchain data alone and would need verification from the exchange.
A second exchange touchpoint was also identified, linked to the later exploit wave. The funds were deposited into what Solido assessed as customer-specific exchange infrastructure before being swept into an omnibus wallet.
What Solido Is Asking For
Solido is now asking exchanges to confirm whether the flagged addresses belong to their platforms. It is also requesting that holds be placed on any traced deposits and that account records be preserved for potential law enforcement use.
The company made clear it is not asking for blanket freezes on unrelated customer accounts and is not claiming any exchange knowingly helped the attacker.
Since the attack, Solido has applied contract-level fixes that disable the minting path used in the exploit. The report noted that simply shutting down the front end was not enough to stop the second wave.
Solido said its findings are based on blockchain evidence only and do not name any real-world individuals.







