Skip to main content
6 min read

Solido Cash Exploit: 293.7M
SUPRA Drained via Oracle Misassignment

293.7 million SUPRA was extracted from Solido Cash via a stale SOLID oracle fallback; 84.1% reached suspected exchange infrastructure during two exploit waves.

AUTOSEC.DEVAUTOSEC.DEV
Solido Cash Exploit: 293.7M SUPRA Drained via Oracle Misassignment
  • Incident Date: July 23, 2026
  • Target: Solido Cash
  • Target Overview: Solido Cash is Solido Money's over-collateralised debt position and stablecoin product on Supra mainnet. Users deposit supported assets as collateral to mint CASH.
  • Total Loss: 293,705,544.97 SUPRA in net attacker proceeds; Solido's official report does not provide a fiat-loss estimate
  • Primary Incident Address: 0x473da897ccc9e1932a3756d1811d08e83b7ba0387cd42c5f9f89c64ccb1fd14b
  • Wave A Exploit Transaction: 0x5d9a6fd31c865a2f93fe4c2a7338c24373b66d82dd171c96f303deb8e412de18
  • Attack Vector: Oracle pricing anomaly caused by a stale-feed fallback misassignment

Incident Review & Technical Details

1. Attack Path

  1. A stale SOLID feed resolved to the wrong price: SOLID was listed as backstop collateral, but its asset-specific oracle feed had gone stale. Instead of failing closed, the collateral pricing path fell back to the prevailing CASH quote and returned 0.99919999, valuing each SOLID unit near par even though the token could be acquired for approximately 22.2 SUPRA on the market.
  2. Wave A atomically converted the mispricing into SUPRA: At 18:21 UTC, the attacker used one Move transaction to buy SOLID, open troves, mint CASH, and sell the newly minted debt into Atmos liquidity. The largest loop deposited 692,800 SOLID and minted 464,176 CASH; across the transaction, 470,677 CASH was minted and 470,675 CASH was sold, producing 266,778,767.97 SUPRA in net proceeds.
  3. Wave B repeated the exploit during the containment gap: With front-end suppression in place but the permissionless contracts still enabled, a second operation began at 21:12 UTC. Five fresh wallets sequentially bought SOLID, opened troves, minted and sold CASH, then relayed the growing SUPRA balance to the next wallet. The sequence minted 338,374.55 CASH and produced another 26,926,777 SUPRA net of its 398,044 SUPRA starting capital.
  4. Most proceeds reached suspected exchange infrastructure: The two waves produced a combined 293,705,544.97 SUPRA in net proceeds. Solido traced 220 million SUPRA to an address believed to be a Gate.io deposit address and 26,926,777 SUPRA from Wave B to an unidentified exchange deposit flow. The remaining 46,778,767.97 SUPRA was still unmoved at attacker-linked addresses at the report's evidence cutoff.

2. Impact Scope

  • Protocol-Level Loss: The two waves yielded 293,705,544.97 SUPRA in net attacker proceeds. Solido's official report treats these as event-level transaction measures and applies no exchange rate, so this article does not present an unsupported USD conversion.
  • Liquidity-Provider Exposure and CASH Depeg: The direct realised loss fell on liquidity providers in CASH-paired Atmos and Dexlyn pools. Their SUPRA inventory was exchanged for newly minted CASH, causing what Solido described as a significant CASH depeg. Solido's initial update said most of the affected liquidity belonged to the Supra Foundation, the primary liquidity provider.
  • Residual Protocol Shortfall: The incident troves left 809,051.55 CASH of debt outstanding against SOLID collateral whose realisable market value was materially below the protocol's recorded valuation. Solido described this shortfall as a protocol-level obligation distinct from the LP losses.
  • Depositor and Borrower Scope: No pre-existing depositor or borrower position was liquidated, seized, or drawn upon. The attack opened new troves, and the liquidation function continued to operate normally. Solido separately said it was reviewing repayments made with CASH bought after the depeg.
  • Solido Flow Scope: Solido Flow and its stSUPRA vault held no CASH and were not reachable through the mint-and-sell path. The vault was paused as a precaution rather than in response to a loss.

3. Official Statements

  • Initial incident update: On July 24, 2026, Solido Money said unauthorized CASH had been minted and sold on DEXs, draining CASH-paired liquidity and causing a significant depeg. The team said protocol-held funds appeared safe under its then-current understanding and paused Flow, Cash, and Grow while investigating.
  • Forensic conclusion: In its consolidated forensic report, Solido classified the root cause as an oracle misassignment on the SOLID collateral listing combined with insufficient risk limits. It explicitly distinguished the failure from reentrancy and market manipulation because the incorrect valuation already existed in the protocol's pricing path.
  • Containment and recovery requests: Solido reported that contract-level controls disabled collateral operations between 23:05 and 23:12 UTC, closing the mint path while leaving liquidation available. It asked receiving exchanges to confirm address ownership, hold only the specifically traced deposits, and preserve KYC, login, IP, and device records for lawful requests.

4. Investigation Progress

As of the report's July 23, 2026, 23:12 UTC evidence cutoff, all collateral operation flags returned disabled and the Grow and Flow vaults were paused. The second wave demonstrated why hiding a front end does not contain permissionless contracts: the same pricing defect remained callable until the on-chain flags changed roughly two hours after Wave B began.

Approximately 246,926,777 SUPRA, or 84.1% of net proceeds, was assessed as having reached centralised-exchange infrastructure and may therefore be within custodial reach. That classification remains a behavioural inference pending confirmation by the exchanges. Solido did not attribute either wave to a real-world identity, and although the waves shared the same defect, assets, venue, and timing, the report found no wallet overlap sufficient to establish a common operator.


AUTOSEC.DEV Solution

Preventing this failure mode requires oracle integrations that fail safely and containment controls that operate at the contract layer as soon as a pricing anomaly is detected.

  1. Secure Code Review — Solido Cash treated a stale SOLID feed as a near-par 0.99919999 CASH-denominated value, turning an availability fallback into an unsafe collateral valuation. AUTOSEC.DEV reviews oracle selection and fallback paths with stale-data tests, per-asset feed validation, invariant fuzzing, and fail-closed conditions that prevent minting whenever a listing cannot produce a fresh, market-grounded price.
  2. Security Strategy & Planning — Wave B extracted 26,926,777 SUPRA while front-end suppression was active but the contracts remained permissionless and enabled. AUTOSEC.DEV designs on-chain incident controls around per-collateral mint caps, oracle-versus-DEX deviation breakers, atomic pause procedures, and response runbooks that distinguish user-interface shutdown from actual protocol containment.

Reference