Solido Money has published a forensic report on its recent exploit. It says it traced around 84% of the attacker’s proceeds to centralized exchange infrastructure while requesting assistance from exchanges to help preserve and recover the funds.
The report reconstructs the incident through on-chain analysis. It concludes that two separate exploit waves generated a combined 293.7 million SUPRA in net proceeds after exploiting the same oracle pricing flaw.
Solido stressed that its findings are based on blockchain evidence and do not identify any real-world individuals or accuse exchanges of facilitating the attack.
Report identifies two exploit waves
According to the report, the attack unfolded in two operationally distinct waves on July 23, both exploiting an oracle misassignment that caused the protocol to value collateral at nearly one U.S. dollar despite its market price being only a fraction of that amount.
The attacker used the mispriced collateral to mint CASH before selling it for SUPRA.
Solido said the first wave was executed through a single atomic transaction. In contrast, the second repeated the same strategy manually across five wallets several hours later. Together, the two waves minted 809,052 CASH and generated net proceeds of 293.7 million SUPRA.
The report concluded that the exploit stemmed from an oracle misassignment combined with insufficient risk limits, rather than a reentrancy vulnerability or market manipulation.
Solido seeks exchange assistance
Solido’s analysis found that approximately 246.9 million SUPRA, representing about 84% of the proceeds, reached centralized exchange infrastructure. The remaining 46.8 million SUPRA remained on-chain at the time of the report.
For the first exploit wave, the report said 220 million SUPRA was traced to a suspected Gate.io deposit address. However, it emphasized that exchange ownership could not be confirmed from on-chain data alone and would require verification by the platform.
The report also identified a second exchange touchpoint linked to the later exploit wave, stating that the proceeds were deposited into an address assessed as customer-specific exchange infrastructure before being swept into an omnibus wallet.
Solido noted that these conclusions are behavioural assessments based on blockchain activity and not established facts.
Protocol requests targeted fund preservation
As part of its response, Solido asked exchanges to confirm whether specific addresses belong to their platforms, place holds on traced incident-related deposits where appropriate and preserve account records for potential law enforcement requests.
The company said it was not requesting freezes on unrelated customer balances or asserting that any exchange knowingly facilitated the exploit.
The report also said contract-level containment measures have since been applied, disabling the minting path used in the exploit. They noted that front-end shutdowns alone were insufficient to prevent the second attack wave.
Final Summary
- Solido’s forensic report said two exploit waves generated 293.7 million SUPRA in net proceeds through an oracle misassignment.
- The protocol said about 84% of the proceeds reached exchange infrastructure and asked exchanges to help preserve and trace the funds.
