290 million SUPRA stolen, foundation funds hit hard.

CN
5 hours ago

On July 28, 2024, the DeFi platform Solido Money suddenly experienced an abnormally large transfer on-chain, revealing an attack targeting a protocol vulnerability. According to path data monitored and disclosed by the on-chain security agency PeckShield, and data from AiCoin, the attacker stole approximately 293.7 million SUPRA from addresses associated with the protocol in a very short time. About 220 million of these tokens were directly directed to an address suspected to be a deposit address for the Gate exchange. The entire process seemed almost like a “single line” pushing chips toward the exchange entrance. Even more dramatically, Solido Money’s official report later confirmed that about 90% of the affected assets belonged to the relevant foundation, corresponding to approximately 264.3 million SUPRA. This means that in this seemingly “platform hack” on-chain incident, the real victims were not scattered retail positions, but the foundation’s treasury, which was supposed to provide long-term support for the ecosystem.

On the day of the vulnerability outbreak: 293.7 million SUPRA swept away

On July 28, 2024, Solido Money's on-chain data suddenly showed severe anomalies. Shortly after the attack occurred, substantial transfers began to appear from addresses related to the protocol. According to statistics from a single on-chain monitoring source, approximately 293.7 million SUPRA were drained from related addresses. At this time, the official had not released any technical explanations, leaving the outside world to infer from the transaction trajectories that this was a precise exploitation of a protocol vulnerability, rather than ordinary operational adjustment or fund migration.

According to the monitoring source and tracking data publicly disclosed by PeckShield on social media, the stolen SUPRA was not widely dispersed but was highly concentrated in a few interrelated addresses, forming a distinct “collect-then-redistribute” structure. Part of the funds was subsequently pushed along a single path outward, with about 220 million SUPRA directed into an address suspected to be a deposit address for the Gate exchange, while the remaining chips began to spread to other unknown addresses. This abrupt concentrated outflow and focus toward the exchange entrance allowed security agencies like PeckShield to capture the anomaly on the same day and quickly amplify it to the public opinion arena, making this attack that initially only occurred on-chain visible to the entire market in a very short time.

200 million SUPRA rush to the exchange: how hackers find an exit

According to AiCoin data (cited from a single on-chain analysis source), of the approximately 293.7 million stolen SUPRA, about 220 million were concentrated into an address marked by multiple parties as a suspected deposit entrance for the Gate exchange. The past behavior of this address exhibited typical characteristics of concentrated inflows, resembling a unified payment channel for the exchange rather than a typical retail user's wallet. This also indicates that the attackers were not testing around on-chain; instead, they directly pushed the majority of their chips toward a gap that could lead to a matchmaking market.

Choosing to quickly send chips into a suspected exchange entrance implies easy speculation about their underlying motives: large-scale tokens entering centralized platforms are typically seen as potential precursors for cashing out or hedging. The hackers might have hoped to take advantage of the order depth at the exchange to sell in batches to lessen the price impact of each sale, or to hedge against price volatility risks using derivative instruments, locking in some profits off-chain. However, all of this remains at the level of speculation; as of current publicly available information, no clear trading records related to specific selling, shorting, or cross-product hedging have emerged. It is equally important that the outside world has not yet grasped whether Gate has identified the related inflows and taken freezing measures, as the exchange has not issued a public statement regarding the disposal of that address, leaving uncertain the critical variable of whether the attackers can successfully exit through the exchange.

90% of chips from the foundation: trust deficit begins to accumulate

As the attack path was gradually restored on-chain, the structure of the damaged funds quickly shifted the focus of contradictions from “how ruthless the hackers are” to “how fragile the foundation is.” According to AiCoin data, Solido Money's official report stated that approximately 90% of the affected funds belonged to the relevant foundation, corresponding to about 264.3 million SUPRA. This means that in the theft of 293.7 million SUPRA, the largest direct victim was not the ordinary users scattered in various locations, but the project itself, which entrusted a significant amount of chips to the protocol. The direct losses of ordinary users accounted for a relatively low proportion and could not dilute a more glaring fact: the foundation had concentrated the majority of its vital assets on a single DeFi platform and a few addresses.

The high concentration of assets in one protocol and a few addresses is now brutally “validated” by the attackers. In community discussions, the criticism began to turn toward the foundation's asset management and risk control awareness: why were hundreds of millions of SUPRA allowed to remain in such a structure that could be drawn away in one go? Why was there no more explicit diversification strategy, emergency plan, and isolation mechanism? Although the foundation's name and specific structure have not yet been disclosed in public materials, this does not prevent the outside world from making an intuitive judgment—when the party holding governance power and resource allocation is the first to suffer in a security incident, the project's governance stability, the community's trust in the official commitments, and the expectations of potential partners for long-term support plans will inevitably be repriced due to this concentrated damage.

Another DeFi platform fails: how security deficits drag down the narrative

When it is proven that governance and financial hubs are not “security buffers” but primary victims, the Solido Money incident becomes more than just an individual protocol incident; it enters the sequence of frequent DeFi attacks over the past several years and is interpreted as another concentrated exposure of the industry's long-term insufficient security investment. According to AiCoin data, approximately 293.7 million SUPRA were drawn from addresses related to the protocol, which were then rapidly directed toward the suspected exchange entrance. This clearly visible path of fund shifting on-chain serves as an alarm bell to market participants who are already highly sensitive to similar incidents—what “open finance” brings is not a dividend of freedom, but a recurring systemic security anxiety.

Even more challenging is that as of current public information, Solido Money has not disclosed the specific technical methods involved in the attack. The outside world cannot confirm whether it was a smart contract logic flaw, permission configuration defect, or other architectural missteps. The lack of a complete technical review and subsequent audit results means that whether it is potential integrators, ecosystem partners, or users already exposed to the protocol, it is difficult to assess whether the risks have been isolated or if similar hidden hazards have not yet been discovered. Under this premise, the project's “storytelling” space is significantly compressed: brand image will face repeated questioning in every piece of security public opinion, other protocols will prioritize security discounts when considering integration or liquidity cooperation, and new users will tend to place Solido Money on a “blacklist” of platforms with security records, responding to this unresolved technical incident with more conservative participation methods or even a wait-and-see attitude. In light of the obscured technical details, this security deficit is now biting back against Solido Money and all the narrative foundations upon which its ecosystem relies.

What to watch next: exchange actions and foundation self-rescue

What truly determines the direction of this crisis are two yet unclear clues: one is whether the exchange will choose to freeze related assets and cooperate with on-chain recovery after approximately 220 million stolen SUPRA flow into the suspected Gate deposit address; the other is when Solido Money and the relevant foundation will present a timeline and demarcated responsibility asset recovery and user compensation plan. As of current public information, Gate has not issued any disposal announcements regarding these addresses, nor has the project revealed a complete self-rescue plan. This means that regardless of how the chips concentrated at the exchange entrance are handled, or how to fill the approximately 264.3 million and 90% foundation-owned damaged assets, everything remains uncertain. Theoretically, the foundation could attempt to restore trust through repurchases, phased compensation, external financing, and rebuilding security systems, but without official commitments, these remain mere speculations rather than established plans. Ultimately, the real scale of losses, recovery rates, and resolution details will directly outline the event's impact over time. For SUPRA holders, the risks of concentrated holdings and single-platform exposure have become a real case; for a broader range of DeFi participants, the safety governance and fund dispersion will become essential prior conditions to be accountable for any protocol until they gain clarity on exchange actions and the strength of the foundation's self-rescue efforts. This will become an unavoidable core variable for SUPRA holders and all DeFi participants when assessing platform credibility.

Join our community to discuss and become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink