The core vulnerability was an oracle misassignment in Solido Cash's collateral valuation system — specifically, a stale or misconfigured price feed used to value SOLID collateral . The protocol relied on an oracle price for SOLID that had become outdated or was incorrectly mapped, causing the collateral to be valued far above its real market price . By depositing SOLID as collateral at this inflated valuation, the attacker was able to withdraw 293.7 million SUPRA tokens — far exceeding what legitimate collateral should have allowed .
The exploit unfolded in two separate attack waves, both exploiting the same vulnerability :
Security firm PeckShield confirmed the breach and the approximate loss .
Critically, approximately 90% of the stolen funds belonged to the Solido Foundation itself, not to retail users. This means the foundation — not individual lenders or borrowers — absorbed nearly all the loss .
Solido Money published a forensic report detailing the on-chain trail:
The Solido exploit is not an isolated incident. Just 12 days earlier, on July 11, 2026, the Hedera-based lending protocol Bonzo Lend lost ~$9.05 million through a related oracle exploit .
Bonzo Lend (July 11, 2026):
Both protocols — Solido Money and Bonzo Lend — relied on Supra as their oracle provider . Two different failure modes emerged from the same infrastructure:
The two incidents, occurring within two weeks of each other, have put the Supra oracle ecosystem under heightened scrutiny. Security analysts are calling for stricter timestamp validation, feed-decency normalization, and multi-source aggregation to prevent similar exploits .
The Solido exploit underscores a critical lesson: when price feeds break — whether through stale data or a forged signature — the damage can cascade across an entire ecosystem.