A single oracle misconfiguration was all it took. On July 23, 2026, the Solido Money hack stripped approximately 293.7 million SUPRA tokens from the protocol in two separate attack waves — and within days, on-chain forensics had traced the bulk of those funds to centralized exchange infrastructure, with a significant portion pointing toward a suspected Gate.io deposit address.
Summary
Key takeaways
- The Solido Money hack drained approximately 293.7 million SUPRA tokens through an oracle misassignment vulnerability that caused collateral to be massively overvalued.
- Two exploit waves minted a combined 809,052 CASH tokens, which were sold for SUPRA as net proceeds.
- Around 84% of stolen tokens — approximately 246.9 million SUPRA — were traced to centralized exchange infrastructure.
- Approximately 220 million SUPRA was linked to a suspected Gate.io deposit address, though blockchain data alone cannot confirm platform ownership.
- Solido has applied contract-level fixes disabling the exploited minting path and is requesting exchanges to freeze flagged funds and preserve records for law enforcement.
Solido Money Hack Drains 293.7 Million SUPRA Tokens
The exploit did not rely on sophisticated code injection or a novel cryptographic attack. It exploited something more fundamental: a flaw in how the protocol assigned value to collateral. The oracle misassignment made the system believe deposited collateral was worth nearly one U.S. dollar when its actual market price was only a fraction of that. Once that pricing gap was in place, the rest followed logically — and profitably for the attacker.
How the Exploit Worked
With collateral artificially inflated in value, the attacker minted CASH tokens far beyond what the real collateral could justify. Those CASH tokens were then sold for SUPRA, converting a pricing illusion into real token holdings. Blockchain security firm PeckShield confirmed the attack and noted that roughly 90% of the affected funds belonged to the Supra Foundation, meaning the losses were heavily concentrated rather than spread across retail users.
The attack unfolded in two waves. The first was executed in a single atomic transaction — fast, clean, and difficult to interrupt. The second wave came hours later, manually repeated across five separate wallets using the same technique. Together, the two waves minted 809,052 CASH tokens and generated 293.7 million SUPRA in net proceeds.
What makes this particularly significant is the second wave. Solido’s post-incident report noted that simply disabling the protocol’s front end was not enough to stop it. The vulnerability existed at the contract level — which is exactly where the fix eventually had to be applied.
Tracing Stolen Funds to Centralized Exchanges
Roughly 84% of the stolen SUPRA — approximately 246.9 million tokens — was traced to centralized exchange infrastructure through on-chain analysis. That narrows the recovery window significantly, since centralized platforms hold the keys to user identity in ways that decentralized protocols cannot.
The Gate.io Connection
For the first exploit wave, Solido’s forensic report traced approximately 220 million SUPRA to a suspected Gate.io deposit address. The protocol was careful to note that blockchain data alone cannot confirm whether that address belongs to Gate.io — only the exchange itself can verify that. A second exchange touchpoint was identified in relation to the later wave, where funds were deposited into what appeared to be customer-specific exchange infrastructure before being swept into an omnibus wallet.
This distinction matters. The path from stolen funds to exchange omnibus wallets is a well-worn route in crypto theft cases — once assets reach an omnibus pool, they become far harder to isolate without direct cooperation from the exchange. Time is a real factor here.
Response Measures and Security Fixes
Solido’s response has moved on two parallel tracks: a public appeal to exchanges and a technical patch at the contract level.
Requests to Exchanges to Freeze and Preserve Records
Solido has formally asked exchanges to confirm whether the flagged addresses belong to their platforms, place holds on any traced deposits, and preserve account records for potential law enforcement use. The protocol was explicit that it is not requesting blanket freezes on unrelated customer accounts and is not accusing any exchange of knowingly facilitating the attack. The ask is targeted and procedural — the kind of cooperation that typically precedes a formal law enforcement referral.
Contract-Level Fixes Disabling the Vulnerable Minting Path
On the technical side, contract-level fixes have been applied to disable the minting path that the attacker exploited. The second wave of the attack demonstrated why front-end restrictions are insufficient when the underlying smart contract logic remains vulnerable — patching the interface without addressing the contract would have left the door open. The fix addresses the root cause: the oracle misassignment that allowed collateral overvaluation in the first place.
The broader implication here is familiar but persistently underappreciated in DeFi: oracle integrity is protocol security. When the price feed is wrong, every downstream calculation — collateral ratios, liquidation thresholds, mintable amounts — inherits that error. A single misassigned oracle effectively rewrote the protocol’s economic assumptions in real time, and the attacker was ready to capitalize on it.
For Solido, the recovery path now runs almost entirely through exchange cooperation. With $900,000 estimated in losses and the protocol’s TVL sitting at approximately $950,000 following the attack, the financial stakes are real but not catastrophic at the system level. What matters more is whether exchanges respond quickly enough to freeze the flagged deposits before the funds move further — a race between forensic speed and the attacker’s next transaction.
FAQ
How did the Solido Money hack occur?
The attacker exploited an oracle misassignment flaw that massively overvalued collateral within the protocol, allowing them to mint CASH tokens backed by collateral worth far less than the system believed. Those tokens were then sold for SUPRA, converting the pricing error into real token proceeds.
How much of the stolen SUPRA tokens were traced to exchanges?
Around 84% of the total stolen amount — approximately 246.9 million SUPRA — was traced to centralized exchange infrastructure through on-chain analysis conducted by Solido Money.
What steps has Solido Money taken after the hack?
Solido applied contract-level fixes to disable the exploited minting path and formally requested that exchanges freeze flagged funds and preserve account records for potential law enforcement proceedings.
Is Solido accusing exchanges of complicity in the hack?
No. Solido explicitly clarified that it is not accusing any exchange of knowingly assisting the attacker and is not requesting blanket freezes on unrelated accounts. The requests are targeted to specific flagged addresses identified through on-chain tracing.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

