Solido Money Hack Drains 293.7M SUPRA Tokens via Oracle Flaw

SUPRA-5.82%
Key Takeaways
  • Solido Money suffered a hack on July 23, 2026, draining 293.7 million SUPRA tokens through oracle misconfiguration.
  • The attacker minted 809,052 CASH tokens exploiting overvalued collateral, with 246.9 million SUPRA traced to centralized exchanges.
  • Solido applied contract-level fixes and requested exchanges freeze flagged deposits and preserve records for law enforcement.

Solido Money suffered a hack on July 23, 2026, that drained approximately 293.7 million SUPRA tokens from the protocol through two separate attack waves. The exploit was caused by an oracle misconfiguration that massively overvalued collateral, allowing the attacker to mint CASH tokens backed by collateral worth far less than the system calculated. Within days of the incident, on-chain forensics traced around 84% of the stolen tokens—approximately 246.9 million SUPRA—to centralized exchange infrastructure, with a significant portion pointing toward a suspected Gate.io deposit address. Blockchain security firm PeckShield confirmed the attack and noted that roughly 90% of the affected funds belonged to the Supra Foundation. The oracle misassignment created a pricing gap that enabled the attacker to convert an artificial valuation error into real token holdings, highlighting fundamental vulnerabilities in how DeFi protocols assign value to collateral.

Oracle Misconfiguration Enables 809,052 CASH Token Minting

The exploit did not rely on sophisticated code injection or novel cryptographic attacks. Instead, it exploited a flaw in how the protocol assigned value to collateral. The oracle misassignment made the system believe deposited collateral was worth nearly one U.S. dollar when its actual market price was only a fraction of that amount.

With collateral artificially inflated in value, the attacker minted CASH tokens far beyond what the real collateral could justify. Those CASH tokens were then sold for SUPRA, converting the pricing illusion into real token holdings. The attack unfolded in two waves. The first wave was executed in a single atomic transaction. The second wave came hours later, manually repeated across five separate wallets using the same technique. Together, the two waves minted 809,052 CASH tokens and generated 293.7 million SUPRA in net proceeds.

Solido's post-incident report noted that simply disabling the protocol's front end was not enough to stop the second wave. The vulnerability existed at the contract level, which is where the fix eventually had to be applied.

246.9 Million SUPRA Traced to Centralized Exchange Infrastructure

Roughly 84% of the stolen SUPRA—approximately 246.9 million tokens—was traced to centralized exchange infrastructure through on-chain analysis. That narrows the recovery window significantly, since centralized platforms hold the keys to user identity in ways that decentralized protocols cannot.

220 Million SUPRA Linked to Suspected Gate.io Deposit Address

For the first exploit wave, Solido's forensic report traced approximately 220 million SUPRA to a suspected Gate.io deposit address. The protocol noted that blockchain data alone cannot confirm whether that address belongs to Gate.io—only the exchange itself can verify that. A second exchange touchpoint was identified in relation to the later wave, where funds were deposited into what appeared to be customer-specific exchange infrastructure before being swept into an omnibus wallet.

This distinction matters. The path from stolen funds to exchange omnibus wallets is a well-worn route in crypto theft cases—once assets reach an omnibus pool, they become far harder to isolate without direct cooperation from the exchange.

Solido Applies Contract Fixes and Requests Exchange Cooperation

Solido's response has moved on two parallel tracks: a public appeal to exchanges and a technical patch at the contract level.

Solido Requests Exchanges Freeze Flagged Deposits and Preserve Records

Solido has formally asked exchanges to confirm whether the flagged addresses belong to their platforms, place holds on any traced deposits, and preserve account records for potential law enforcement use. The protocol stated it is not requesting blanket freezes on unrelated customer accounts and is not accusing any exchange of knowingly facilitating the attack. The requests are targeted to specific flagged addresses identified through on-chain tracing.

Contract-Level Fixes Disable Vulnerable Minting Path

Contract-level fixes have been applied to disable the minting path that the attacker exploited. The second wave of the attack demonstrated why front-end restrictions are insufficient when the underlying smart contract logic remains vulnerable. The fix addresses the root cause: the oracle misassignment that allowed collateral overvaluation.

With $900,000 estimated in losses and the protocol's TVL sitting at approximately $950,000 following the attack, the recovery path now runs almost entirely through exchange cooperation.

FAQ

How did the Solido Money hack occur?

The attacker exploited an oracle misconfiguration that massively overvalued collateral within the protocol, allowing them to mint CASH tokens backed by collateral worth far less than the system believed. Those tokens were then sold for SUPRA, converting the pricing error into real token proceeds.

How much of the stolen SUPRA tokens were traced to exchanges?

Around 84% of the total stolen amount—approximately 246.9 million SUPRA—was traced to centralized exchange infrastructure through on-chain analysis conducted by Solido Money.

What steps has Solido Money taken after the hack?

Solido applied contract-level fixes to disable the exploited minting path and formally requested that exchanges freeze flagged funds and preserve account records for potential law enforcement proceedings.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments