BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

Solido Foundation Held 90% of Funds Lost in Solido Cash Exploit

Solido Cash Exploit Report Reveals Foundation's Major Losses New details from Solido Money's incident report reveal that roughly 90% of the funds lost in the Cash exploit reportedly belonged

AnonymousCryptoCompass newsroom
July 28, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

Solido Cash Exploit Report Reveals Foundation's Major Losses 

New details from Solido Money's incident report reveal that roughly 90% of the funds lost in the Cash exploit reportedly belonged to the protocol's own foundation. The report also confirms that around 220 million of the stolen SUPRA were deposited into a suspected Gate exchange deposit address, adding fresh weight to an already significant attack on the Supra-based lending protocol.

Solido Cash Exploit Report Reveals Foundation's Major Losses

Source: X SolidoMoney

What Happened

The Solido Cash exploit unfolded in two separate waves on July 23, 2026, both exploiting the same flaw in how the protocol priced one of its collateral assets.

  • Wave A: At 18:21:35 UTC, the attacker executed a single transaction that chained several steps together — swapping tokens, depositing them as collateral, and minting new CASH. This move alone netted 266,778,767.97 SUPRA.

  • Wave B: About three hours later, starting at 21:12 UTC, the same trick was repeated manually across five different wallets, bringing in another 26,926,777 SUPRA.

Combined, the two waves created 809,051.55 CASH worth of new debt and pulled out 293,705,544.97 SUPRA in total.

How the Exploit Unfolded

In Wave A, everything happened automatically in one transaction: buy cheap collateral, deposit it, mint CASH against it, then sell that token for SUPRA. Wave B did the same thing, just manually. 

The attacker funded the first wallet with 398,044 SUPRA from an address that looks like it belongs to a centralized exchange, then moved money through five wallets one after another, each one consolidating the stolen funds before passing it along to the next.

Root Cause

The report attributes the Solido Cash exploit to an oracle misassignment. SOLID, used as backstop collateral, was tied to a price feed that went stale. 

When that happened, the protocol's fallback logic valued SOLID using the token quote instead of its real market price, letting the attacker mint far more CASH than the collateral was actually worth. 

Solido Money classified this as a pricing-path defect combined with insufficient risk limits, not a reentrancy bug or market manipulation. 

Market Impact

Metric

Amount

Total stolen

293,705,544.97 $SUPRA

Sent to a suspected Gate.io address

220,000,000 $SUPRA (74.9%)

Still sitting on-chain, untouched

46,778,767.97 $SUPRA (15.9%)

Moved to an unidentified exchange

26,926,777 $SUPRA (9.2%)

New token debt created

809,051.55

About 84% of everything taken ended up on exchanges, which means there's a real chance it could still be recovered if those platforms confirm the accounts and freeze the deposits.

User Impact

According to the incident report, user deposits and existing loan positions were not directly affected. Existing depositor funds and borrower positions were not directly impacted. 

Both waves worked by opening brand-new positions, not by draining existing ones, and the system's liquidation process kept running fine the whole time. 

The people who actually lost money were liquidity providers in the token trading pools, since their $SUPRA got swapped out for the freshly minted, effectively worthless token.

Solido's other product, a separate vault called Solido Flow, wasn't touched at all — it got paused just to be safe, not because anything went wrong there.

The team moved to shut things down a few hours later. Between 23:05 and 23:12 UTC, Solido Money disabled all six collateral listings on the protocol, closing off the loophole for good. 

They've also reached out to the exchanges that received the stolen funds, asking them to confirm who owns those accounts, freeze the relevant deposits, and hold onto records in case law enforcement needs them.

Conclusion

The Solido Cash exploit shows how a single stale price feed can cascade into a multi-million-dollar loss when fallback pricing logic isn't tightly guarded. 

With contract-level containment now in place and most of the stolen $SUPRA traced to identifiable exchange addresses, recovery may depend heavily on how quickly those platforms cooperate. 

For now, Solido Money says depositor funds remain safe, but the protocol still carries a shortfall tied to the debt created during the incident. 

Disclaimer 

This article is for educational and informational purposes only and should not be considered financial or investment advice. Always conduct your own research before making investment decisions.