Solido Foundation Held 90% of Funds Lost in Solido Cash Exploit

Solido Cash exploit report showing foundation fund losses and SUPRA transfers

Solido Cash Exploit Report Reveals Foundation's Major Losses 

New details from Solido Money's incident report reveal that roughly 90% of the funds lost in the Cash exploit reportedly belonged to the protocol's own foundation. The report also confirms that around 220 million of the stolen SUPRA were deposited into a suspected Gate exchange deposit address, adding fresh weight to an already significant attack on the Supra-based lending protocol.

Solido Cash Exploit Report Reveals Foundation's Major Losses

Source: X SolidoMoney

What Happened

The Solido Cash exploit unfolded in two separate waves on July 23, 2026, both exploiting the same flaw in how the protocol priced one of its collateral assets.

  • Wave A: At 18:21:35 UTC, the attacker executed a single transaction that chained several steps together — swapping tokens, depositing them as collateral, and minting new CASH. This move alone netted 266,778,767.97 SUPRA.

  • Wave B: About three hours later, starting at 21:12 UTC, the same trick was repeated manually across five different wallets, bringing in another 26,926,777 SUPRA.

Combined, the two waves created 809,051.55 CASH worth of new debt and pulled out 293,705,544.97 SUPRA in total.

How the Exploit Unfolded

In Wave A, everything happened automatically in one transaction: buy cheap collateral, deposit it, mint CASH against it, then sell that token for SUPRA. Wave B did the same thing, just manually. 

The attacker funded the first wallet with 398,044 SUPRA from an address that looks like it belongs to a centralized exchange, then moved money through five wallets one after another, each one consolidating the stolen funds before passing it along to the next.

Root Cause

The report attributes the Solido Cash exploit to an oracle misassignment. SOLID, used as backstop collateral, was tied to a price feed that went stale. 

When that happened, the protocol's fallback logic valued SOLID using the token quote instead of its real market price, letting the attacker mint far more CASH than the collateral was actually worth. 

Solido Money classified this as a pricing-path defect combined with insufficient risk limits, not a reentrancy bug or market manipulation. 

Market Impact

Metric

Amount

Total stolen

293,705,544.97 $SUPRA

Sent to a suspected Gate.io address

220,000,000 $SUPRA (74.9%)

Still sitting on-chain, untouched

46,778,767.97 $SUPRA (15.9%)

Moved to an unidentified exchange

26,926,777 $SUPRA (9.2%)

New token debt created

809,051.55

About 84% of everything taken ended up on exchanges, which means there's a real chance it could still be recovered if those platforms confirm the accounts and freeze the deposits.

User Impact

According to the incident report, user deposits and existing loan positions were not directly affected. Existing depositor funds and borrower positions were not directly impacted. 

Both waves worked by opening brand-new positions, not by draining existing ones, and the system's liquidation process kept running fine the whole time. 

The people who actually lost money were liquidity providers in the token trading pools, since their $SUPRA got swapped out for the freshly minted, effectively worthless token.

Solido's other product, a separate vault called Solido Flow, wasn't touched at all — it got paused just to be safe, not because anything went wrong there.

The team moved to shut things down a few hours later. Between 23:05 and 23:12 UTC, Solido Money disabled all six collateral listings on the protocol, closing off the loophole for good. 

They've also reached out to the exchanges that received the stolen funds, asking them to confirm who owns those accounts, freeze the relevant deposits, and hold onto records in case law enforcement needs them.

Conclusion

The Solido Cash exploit shows how a single stale price feed can cascade into a multi-million-dollar loss when fallback pricing logic isn't tightly guarded. 

With contract-level containment now in place and most of the stolen $SUPRA traced to identifiable exchange addresses, recovery may depend heavily on how quickly those platforms cooperate. 

For now, Solido Money says depositor funds remain safe, but the protocol still carries a shortfall tied to the debt created during the incident. 

Disclaimer 

This article is for educational and informational purposes only and should not be considered financial or investment advice. Always conduct your own research before making investment decisions.

Bablu Singh Nirwan

About the Author Bablu Singh Nirwan

English Blog Writer at coingabbar.com

Bablu Singh Nirwan is a passionate Content Writer with 6 months of experience in writing informative and engaging content related to blockchain, cryptocurrency, Web3, and digital finance. He has a strong ability to research emerging trends, simplify technical topics, and create SEO-optimized articles that provide value to a wide audience. His work emphasizes clarity, originality, and accuracy while covering market updates, educational content, and industry insights. Dedicated to continuous learning, Bablu stays informed about the latest developments in the crypto space and is committed to producing impactful content that keeps readers informed and engaged.

Leave a comment

Frequently Asked Questions (FAQ)

Faq Got any doubts? Get In Touch With Us
Scroll to Top