Solido Cash Hack

Reported loss $900K
supra
Oracle Issue

What happened

On July 23, 2026, Solido Cash was exploited in two operationally distinct waves that produced 293.7 million SUPRA in net proceeds and 809,051.55 CASH in unauthorized debt, according to Solido’s on-chain forensic report.

Technical root cause

Solido’s report attributes the defect to an oracle misassignment: the CDP’s backstop collateral price resolved to the CASH oracle instead of the collateral asset’s own market, so the protocol treated a low-value asset as near-par USD collateral.

How it happened

In each wave, the attacker acquired the affected collateral cheaply, deposited it, minted CASH against an incorrectly near-par valuation, and sold CASH for SUPRA. The first wave used one atomic transaction; the second repeated the same mechanism through a five-wallet relay during the containment gap.

Protocol details

Classification Stablecoin,Borrowing and Lending / Oracle Manipulation
Protocol Type CDP
Implementation language Move
Protocol links Website @SolidoMoney

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.