Solido Cash Hack
What happened
On July 23, 2026, Solido Cash was exploited in two operationally distinct waves that produced 293.7 million SUPRA in net proceeds and 809,051.55 CASH in unauthorized debt, according to Solido’s on-chain forensic report.
Solido’s report attributes the defect to an oracle misassignment: the CDP’s backstop collateral price resolved to the CASH oracle instead of the collateral asset’s own market, so the protocol treated a low-value asset as near-par USD collateral.
How it happened
In each wave, the attacker acquired the affected collateral cheaply, deposited it, minted CASH against an incorrectly near-par valuation, and sold CASH for SUPRA. The first wave used one atomic transaction; the second repeated the same mechanism through a five-wallet relay during the containment gap.
Protocol details
Security review history
- MoveBit View report
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.