Solido Cash confirmed an oracle pricing exploit drained 293.7 million SUPRA tokens, value roughly $900,000, throughout two separate assault waves. The protocol detailed the incident in a forensic report, tracing round 220 million SUPRA, practically 90% of the stolen funds, to a suspected Gate.io deposit deal with. Solido’s chain now holds simply $950,000 in complete worth locked, and its token is down 94% over the previous yr, a decline that leaves little room to soak up a lack of this measurement.

Supply – Solido Money Incident | Consolidated On-Chain Forensic Report
How the Oracle Misassignment Enabled the Theft
Solido’s report traced the exploit to a single oracle misassignment. The flaw let the protocol worth sure collateral at shut to 1 U.S. greenback, although its actual market worth sat at a fraction of that. Attackers used the mispriced collateral to mint CASH, Solido’s stablecoin, then bought it for SUPRA.
The primary wave ran via one atomic transaction. The second wave, carried out a number of hours later, repeated the identical methodology manually throughout 5 separate wallets, in response to Solido. Mixed, the 2 waves minted 809,052 CASH and generated internet proceeds of 293.7 million SUPRA.
Solido traced about 246.9 million SUPRA, roughly 84% of the entire proceeds, to centralized alternate infrastructure. The remaining 46.8 million SUPRA stayed on-chain on the time the report was revealed.
For the primary wave, the report pointed to a suspected Gate.io deposit deal with holding 220 million SUPRA. Solido pressured that alternate possession can’t be confirmed from on-chain knowledge alone.
For the second wave, the report traced funds to a separate deal with it described as customer-specific alternate infrastructure, earlier than the funds had been swept right into a shared omnibus pockets. Solido cautioned that each traces come from studying pockets conduct on-chain, not from confirmed identities, and that its report doesn’t accuse both alternate of facilitating the assault.
What This Means for SUPRA Holders
Solido’s exploit provides to a run of DeFi protocols dropping funds to oracle failures slightly than sensible contract bugs. An oracle is the value feed a protocol depends on to know what collateral is definitely value, and when it misreads that worth, as Solido’s did, the protocol can let attackers borrow or mint excess of the collateral justifies.
For those who’re nonetheless getting aware of how DeFi lending platforms worth and safe collateral, this exploit is an efficient instance to be taught from. Examine how a mission sources its worth feeds earlier than depositing funds, since that’s precisely the place Solido’s setup failed. The danger is larger on a smaller chain like Solido’s, the place $950,000 in TVL (Whole Worth Locked) leaves little room to soak up one other hit like this one.
It’s additionally not an remoted case. We coated a similar-sized DeFi exploit at Kelp DAO earlier this yr, the place attackers moved a comparable quantity of stolen property via cross-chain infrastructure.
What Occurs Subsequent to the Traced 293.7M SUPRA
Solido stated in its report that it has requested exchanges to assist protect and get well the traced proceeds, with out naming Gate.io immediately. That sort of restoration sometimes is dependent upon an alternate freezing the flagged deposit addresses and utilizing its personal KYC data to determine the account holder, a step Solido can’t take by itself since blockchain knowledge alone doesn’t reveal real-world identities. Cooperation like that has labored earlier than. Arbitrum froze 71 million in stolen Kelp funds earlier this yr after an analogous tracing effort.
Whether or not Gate.io or different platforms verify and freeze the flagged wallets within the days following the July 23 report will decide how a lot of the 293.7 million SUPRA the Supra Basis, which owned near 90% of the stolen funds, can get well.
This text is for informational functions solely and doesn’t represent monetary recommendation. Do your personal analysis earlier than making any funding choices.
What this implies for you: For those who maintain or use SUPRA, this exploit is a reminder {that a} protocol doesn’t want a hacked sensible contract to lose cash. A unsuitable worth studying was sufficient right here, so earlier than you deposit funds wherever, examine whether or not the mission explains the place its worth knowledge comes from and the way it protects that feed from being manipulated.
