NewsCryptoSolido Says 84% of Exploit Proceeds Reached Exchange Infrastructure

Solido Says 84% of Exploit Proceeds Reached Exchange Infrastructure

Author: AMBCrypto·

Key Takeaways

  • •Solido said two exploit waves used the same oracle pricing flaw to generate 293.7 million SUPRA in net proceeds.
  • •The attacker minted 809,052 CASH using overvalued collateral and sold the CASH for SUPRA.
  • •Solido traced about 246.9 million SUPRA to centralized exchange infrastructure, while 46.8 million SUPRA remained on-chain at the time of the report.
  • •The protocol said the exploit stemmed from an oracle misassignment and insufficient risk limits, not from reentrancy or market manipulation.
  • •Solido has implemented contract-level measures to disable the minting path used in the attack and requested targeted exchange cooperation.
Solido Says 84% of Exploit Proceeds Reached Exchange Infrastructure

Solido Money has released a forensic report on its recent exploit, saying it traced roughly 84% of the attacker’s proceeds to centralized exchange infrastructure and has requested help from exchanges to preserve and recover the funds.

The report reconstructs the incident using on-chain analysis. It says two separate exploit waves produced a combined 293.7 million SUPRA in net proceeds after the same oracle pricing flaw was used in both attacks.

Solido emphasized that its conclusions are based on blockchain evidence. The protocol said the report does not identify any real-world individuals and does not accuse exchanges of facilitating the exploit. In DeFi incident reviews, that distinction is important because public ledgers can show transaction flows and wallet behavior, but they generally cannot verify the legal owner of an exchange account without platform records.

Report details two exploit waves

According to the report, the attack occurred in two operationally distinct waves on July 23. Both waves exploited an oracle misassignment that led the protocol to value collateral at nearly one U.S. dollar, even though its market price was only a fraction of that amount.

The attacker used the incorrectly priced collateral to mint CASH, then sold the CASH for SUPRA. Oracle configuration and collateral risk controls are core safeguards for lending and minting protocols because they determine how much value a user can borrow or create against posted assets.

Solido said the first wave was carried out through a single atomic transaction. The second wave, several hours later, repeated the same strategy manually across five wallets. Together, the two waves minted 809,052 CASH and generated net proceeds of 293.7 million SUPRA.

The report concluded that the incident resulted from an oracle misassignment combined with insufficient risk limits. Solido said it was not caused by a reentrancy vulnerability or by market manipulation.

Solido requests exchange cooperation

Solido’s analysis found that about 246.9 million SUPRA, or approximately 84% of the proceeds, reached centralized exchange infrastructure. The remaining 46.8 million SUPRA was still on-chain at the time of the report.

For the first exploit wave, the report said 220 million SUPRA was traced to a suspected Gate.io deposit address. However, Solido stressed that exchange ownership cannot be confirmed from on-chain data alone and would require verification by the platform.

The report also described a second exchange touchpoint connected to the later exploit wave. It said proceeds were deposited into an address assessed as customer-specific exchange infrastructure before being swept into an omnibus wallet.

Solido said these findings are behavioral assessments based on blockchain activity and should not be treated as established facts about the ownership or control of the addresses. The request for exchange verification reflects the limits of on-chain tracing: investigators can follow tokens between addresses, while exchanges may be able to connect deposits to internal account records, subject to their own procedures and applicable legal requests.

Protocol seeks targeted preservation of funds

As part of its response, Solido asked exchanges to confirm whether specific addresses belong to their platforms, place holds on traced incident-related deposits where appropriate, and preserve account records for possible law enforcement requests.

The company said it is not seeking freezes on unrelated customer balances and is not claiming that any exchange knowingly facilitated the exploit.

The report also said Solido has applied contract-level containment measures that disable the minting path used in the exploit. The protocol noted that shutting down the front end alone was not enough to prevent the second attack wave, underscoring that users can still interact with deployed smart contracts through direct calls or alternative interfaces if contract logic remains active.

Solido’s forensic report said the two exploit waves generated 293.7 million SUPRA in net proceeds through the oracle misassignment. The protocol said around 84% of those proceeds reached exchange infrastructure and asked exchanges to help preserve and trace the funds.