Solido Money has released a forensic report into its latest exploit. It is said that he follows around 84% Assistance is requested from exchanges to help protect and recover the revenues transferred by the attacker to the central exchange infrastructure.
The report reconstructs the event through chain analysis. It is concluded that two separate waves of abuse created a combined effect. 293.7 million SUPRA Net income is achieved after exploiting the same oracle pricing flaw.
Solido emphasized that its findings were based on blockchain evidence and did not identify any real-world individuals or accuse the exchanges of facilitating the attack.
Report identifies two waves of abuse
According to the report, the attack took place in two different operational waves. July 23Both exploit an oracle misallocation that causes the protocol to value the collateral at nearly a US dollar, even though the market price is only a small fraction of that amount.
Attacker used mispriced collateral to print CASH before selling it to SUPRA.
The first wave was executed via a single atomic transaction, Solido said. In contrast, the second manually repeated the same strategy on five wallets a few hours later. Two waves printed together 809,052 CASH and earned net income 293.7 million SUPRA.
The report concluded that the exploit was due to incorrect oracle assignment combined with inadequate risk limits, rather than a re-entry vulnerability or market manipulation.
Solido asks for exchange help
Solido’s analysis found: approximately 246.9 million SUPRArepresenting approximately 84% All revenues reached the central exchange infrastructure. what remains 46.8 million SUPRA It remained on the chain during the report.
The report said about the first wave of abuse: 220 million SUPRA It was tracked to a suspicious Gate.io deposit address. However, he emphasized that exchange ownership cannot be verified by on-chain data alone and will need to be verified by the platform.
The report also identified a second exchange touchpoint linked to the later wave of exploits, stating that proceeds were deposited to an address considered a customer-specific exchange infrastructure before being transferred to a multi-purpose wallet.
Solido stated that these results are behavioral assessments based on blockchain activity, not established facts.
Protocol requests protection of targeted funding
As part of its response, Solido asked exchanges to confirm whether certain addresses belong to their platforms, block deposits related to the case where appropriate, and preserve account records for possible law enforcement requests.
The company said it did not request that unrelated customer balances be frozen or claim that any exchange knowingly facilitated this abuse.
The report also noted that contract-level containment measures have since been implemented, disabling the mint route used in exploitation. They noted that front-end shutdowns alone are not enough to prevent a second wave of attacks.
Final Summary
- Solido’s forensic report said that two waves of exploitation produced SUPRA 293.7 million in net income through a false oracle assignment.
- The protocol said about 84% of revenues reach the exchange infrastructure and asked exchanges to help protect and track funds.





