Key Takeaways
- Solido Money released comprehensive forensic analysis detailing the theft of roughly 293.7 million SUPRA tokens from its platform
- Both attack waves exploited an identical vulnerability: an oracle configuration error that dramatically inflated collateral valuations
- Blockchain analysis traced approximately 246.9 million SUPRA tokens (84% of total) to centralized exchange deposit systems
- Investigators identified around 220 million SUPRA moving to what appears to be a Gate.io-linked deposit wallet
- The protocol is requesting exchanges implement holds on identified deposits and maintain records for law enforcement agencies
Following a major security breach on July 23, 2026, Solido Money has published an extensive forensic analysis that maps the movement of stolen cryptocurrency and requests assistance from centralized trading platforms in fund recovery efforts.
According to the investigation, attackers executed two distinct exploit campaigns that collectively netted 293.7 million SUPRA tokens. Each campaign leveraged an identical security weakness — a misconfigured oracle system that dramatically inflated the protocol’s assessment of collateral values.
This configuration error caused the platform to value deposited collateral at approximately one U.S. dollar per unit, despite actual market pricing reflecting only a small fraction of that amount. Exploiting this discrepancy, the attacker deposited artificially overvalued collateral to generate CASH tokens, which were subsequently exchanged for SUPRA.
The initial attack wave occurred through a single bundled transaction. Hours afterward, the second campaign deployed identical tactics manually through five distinct wallets.
Collectively, these operations generated 809,052 CASH tokens and extracted 293.7 million SUPRA in total value. Blockchain security company PeckShield validated the incident and indicated that approximately 90% of compromised assets belonged to the Solido foundation itself.
Tracking the Stolen Assets
Through comprehensive blockchain forensics, Solido’s investigation team determined that roughly 246.9 million SUPRA tokens — representing 84% of total stolen funds — were transferred to centralized exchange deposit infrastructure.
The balance of approximately 46.8 million SUPRA remained in on-chain addresses when the forensic report was released.
Regarding the initial attack wave, investigators tracked 220 million SUPRA to a deposit address believed to be associated with Gate.io. Solido acknowledged this attribution cannot be definitively established through blockchain evidence alone and requires exchange confirmation.
Additional exchange interaction was detected in connection with the subsequent exploit campaign. These funds moved into what researchers identified as user-specific exchange infrastructure before consolidation into a collective custody wallet.
Solido’s Request to Trading Platforms
Solido is calling on cryptocurrency exchanges to verify ownership of the identified deposit addresses. The protocol is also requesting temporary restrictions on traced deposits and preservation of associated account information for possible law enforcement investigations.
The organization emphasized it is not seeking blanket account freezes affecting uninvolved users and makes no suggestion that any exchange platform knowingly facilitated the attacker’s activities.
Following the security incident, Solido implemented smart contract modifications that eliminate the minting functionality exploited in the attack. The report highlighted that merely disabling the user interface proved insufficient to prevent the second attack wave.
Solido clarified that its investigative conclusions rely exclusively on blockchain transaction evidence and do not identify specific individuals.



