On July 23, 2026, an attacker drained 293.7 million SUPRA tokens ( $900,000) from Solido Money by exploiting a stale oracle price feed for SOLID collateral.

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What happened in the Solido Money oracle exploit on July 23, how did the attacker drain 293.7 mil. Article summary: Here is the verified account of the Solido Money exploit, its mechanics, fund tracing, and the broader pattern it fits. ## What Happened on July 23, 2026 On July 23, 2026, an attacker drained **293.7 million SUPRA tokens. Topic tags: general, academic, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, char
On July 23, 2026, an attacker drained 293.7 million SUPRA tokens, valued at roughly $900,000, from the Solido Money lending protocol. The exploit was not a flash loan or a complex smart-contract hack — it was a pricing error. The root cause was an oracle misassignment in Solido Cash's collateral valuation system: a stale or misconfigured price feed for SOLID collateral that let the attacker borrow far more than legitimate collateral should have allowed .
The core vulnerability was an oracle misassignment in Solido Cash's collateral valuation system — specifically, a stale or misconfigured price feed used to value SOLID collateral . The protocol relied on an oracle price for SOLID that had become outdated or was incorrectly mapped, causing the collateral to be valued far above its real market price
. By depositing SOLID as collateral at this inflated valuation, the attacker was able to withdraw 293.7 million SUPRA tokens — far exceeding what legitimate collateral should have allowed
.
The exploit unfolded in two separate attack waves, both exploiting the same vulnerability :
Security firm PeckShield confirmed the breach and the approximate loss .
Critically, approximately 90% of the stolen funds belonged to the Solido Foundation itself, not to retail users. This means the foundation — not individual lenders or borrowers — absorbed nearly all the loss .
Solido Money published a forensic report detailing the on-chain trail:
The Solido exploit is not an isolated incident. Just 12 days earlier, on July 11, 2026, the Hedera-based lending protocol Bonzo Lend lost ~$9.05 million through a related oracle exploit .
Bonzo Lend (July 11, 2026):
Both protocols — Solido Money and Bonzo Lend — relied on Supra as their oracle provider . Two different failure modes emerged from the same infrastructure:
The two incidents, occurring within two weeks of each other, have put the Supra oracle ecosystem under heightened scrutiny. Security analysts are calling for stricter timestamp validation, feed-decency normalization, and multi-source aggregation to prevent similar exploits .
The Solido exploit underscores a critical lesson: when price feeds break — whether through stale data or a forged signature — the damage can cascade across an entire ecosystem.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
On July 23, 2026, an attacker drained 293.7 million SUPRA tokens ( $900,000) from Solido Money by exploiting a stale oracle price feed for SOLID collateral.