Solido Money has published a forensic reconstruction of a July 23 security incident that generated approximately 293.7 million SUPRA in net proceeds across two separate exploit waves. The protocol attributed the incident to an oracle misassignment that caused collateral to be valued near $1 despite trading at a fraction of that price. An oracle is the external price feed a decentralized finance protocol uses to determine how much deposited collateral is worth.
Using the inflated valuation, the operator deposited cheaply acquired collateral, minted CASH against it and sold the newly created tokens for SUPRA. Solido calculated that the two waves produced 809,051.55 CASH and netted 293,705,544.97 SUPRA after deducting the capital used to execute the strategy. The protocol said it would publish a formal remediation and recovery plan within 72 hours.
Two Waves Exploited the Same Pricing Defect
The first wave began at 18:21 UTC and was completed through a single atomic transaction, meaning the swaps, collateral deposits, CASH minting and token sales were bundled into one on-chain operation. That transaction generated approximately 266.8 million SUPRA in net proceeds, according to Solido’s analysis of Supra mainnet records.
Roughly three hours later, a second operation reproduced the same economic sequence manually through five wallets. Each wallet acquired collateral, minted CASH, sold it for SUPRA and transferred the growing balance to the next address. The five-wallet relay generated another 26.9 million SUPRA in net proceeds, although Solido said the available evidence does not establish whether both waves were conducted by the same party.
Solido’s report classified the incident as an oracle misassignment combined with insufficient risk controls, rather than a reentrancy attack or direct market manipulation. The exploitable condition already existed within the protocol’s collateral-pricing path, allowing the operator to borrow substantially more CASH than the collateral’s realizable market value would normally support.
Most Proceeds Reached Suspected Exchange Infrastructure
At the report’s evidence cutoff, Solido had traced approximately 246.9 million SUPRA, or 84.1% of the proceeds, to addresses displaying centralized-exchange characteristics. About 220 million SUPRA was linked to an address suspected of serving as a Gate.io deposit destination, while another 26.9 million was sent through infrastructure associated with an unidentified exchange. The remaining 46.8 million SUPRA was still held at attacker-linked on-chain addresses.
#PeckShieldAlert @SolidoMoney reported an exploit that resulted in ~293.7M $SUPRA being drained. ~220M $SUPRA was deposited into a suspected @Gate deposit address. The report states that ~90% of the affected funds reportedly belonged to the foundation.https://t.co/u9CHHoxVgl
— PeckShieldAlert (@PeckShieldAlert) July 28, 2026
PeckShield subsequently highlighted the reported drain and the transfer to the suspected Gate.io address. However, the exchange classifications remain behavioral assessments derived from public blockchain activity, not confirmations of address ownership or evidence that any platform knowingly facilitated the movement of funds.
Solido has asked potentially affected exchanges to confirm whether the identified addresses belong to their infrastructure, preserve relevant account records and place targeted holds on incident-related deposits where appropriate. The protocol explicitly said it was not seeking blanket freezes of unrelated customer funds or making real-world identity claims. Recovery will therefore depend partly on exchange cooperation and information that cannot be established through public blockchain records alone.
