Article is online

Allbridge Freezes Protocol After $1.65M Flash-Loan Theft from Solana Pools

Allbridge Freezes Protocol After $1.65M Flash-Loan Theft from Solana Pools

Preface

Context: Cross-chain bridges enable transfers between blockchains that otherwise don’t communicate directly. Recently, Allbridge Core — a bridge that moves native stablecoins such as USDC and USDT via liquidity pools — paused its protocol after a flash-loan exploit drained funds from Solana-based liquidity pools. This article explains the incident, the attack technique, immediate responses by Allbridge, and the broader implications for users and the cross-chain ecosystem. The goal is to provide a factual, practical account to help liquidity providers, traders, and observers understand what occurred and what steps may follow.

Lazy bag

Allbridge Core suspended operations after an attacker used a $1.12M flash loan to skew Solana pool ratios and extract roughly $1.65M. The team advised LPs to withdraw and asked traders who profited from temporary pricing imbalances to return funds. The stolen assets were bridged to Ethereum and dispersed; an investigation is ongoing.

Main Body

Onchain analysis and security firms reported that Allbridge Core paused its cross-chain stablecoin protocol following an exploit that resulted in the loss of approximately $1.65 million from its Solana liquidity pools. Allbridge’s Core product uses native stablecoin liquidity pools to transfer assets between blockchains without issuing wrapped tokens, relying on pool ratios to determine swap rates and bridge flows.

The attacker obtained a flash loan of about $1.12 million from Kamino, a Solana lending protocol. Flash loans are uncollateralized loans that must be borrowed and repaid within the same blockchain transaction. Attackers frequently use them to perform fast, capital-intensive operations that manipulate on-chain state before repayment.

In this incident, the attacker rapidly swapped between USDC and USDT inside the affected pools, intentionally altering the pools’ internal ratios. That ratio manipulation produced favorable exchange rates for the attacker, allowing them to withdraw assets at advantageous terms and then bridge those funds out of the Solana ecosystem to an Ethereum address. From there, the funds were distributed across additional addresses. At the time of reporting, security monitors had not confirmed how much of the stolen value remains accessible to the attacker.

Allbridge reacted by pausing the protocol to stop further activity while security teams and auditors investigate the manipulation’s scope and mechanics. The temporary imbalance created an arbitrage opportunity; in response, Allbridge instructed liquidity providers to withdraw funds from the affected pools to limit exposure. The team also publicly requested that traders who profited from the pricing distortion return gains so liquidity providers can be made whole.

This is not Allbridge’s first flash-loan incident. In 2023, the protocol experienced a similar attack that drained roughly $650,000 from its BNB Chain pools. At that time, Allbridge reported recovering most of the funds and adjusted its liquidity and withdrawal calculations to reduce vulnerability. The recurrence highlights persistent risks for protocols that rely on on-chain pool ratios and real-time price relationships without additional safeguards.

Flash-loan exploits typically exploit timing and oracle or pool design weaknesses: an attacker can temporarily overwhelm a pricing mechanism by moving large capital amounts within one transaction, capture value created by the transient state, then repay the loan — all before other actors or external oracles can respond. Protocols that depend exclusively on pool-derived prices, or that lack rate limits, slippage protections, or time-weighted mechanisms, are particularly exposed.

For liquidity providers (LPs) and traders, the incident underscores several practical considerations. LPs should assess smart contract audits, withdrawal mechanics, and whether a protocol has implemented protections such as dynamic fees, oracle smoothing, or limits on single-transaction impacts. Traders should be mindful that apparent on-chain arbitrage opportunities can stem from malicious manipulation and may carry legal and ethical risks if proceeds are retained.

From a mitigation perspective, teams can take steps to reduce flash-loan attack surfaces: introduce time-weighted average pricing, employ off-chain or robust oracle aggregation, add transaction-level limits and dynamic fees that increase during abnormal volatility, and conduct regular third-party audits and incident response drills. Post-incident, transparent communication, active collaboration with security firms and chain explorers, and coordination with exchanges and cross-chain relayers help trace and — when possible — recover misappropriated assets.

Allbridge’s pause and public requests aim to protect LPs and restore balance while investigators trace fund flows across chains. How much is ultimately recoverable depends on the attacker’s actions, on-chain traceability, and whether any counterparties cooperate. The event also renews discussion about the inherent trade-offs in cross-chain liquidity designs: efficiency and atomic transfers vs. susceptibility to rapid, automated manipulation.

In conclusion, the Allbridge incident is a reminder that cross-chain bridges and pool-based stablecoin transfers remain attractive targets for rapid, capitalized attacks. Users and protocols alike should prioritize robust risk controls, improved oracle designs, and crisis response plans. Until structural protections are broadly adopted, participants must remain vigilant and carefully weigh the operational and smart-contract risks of providing or routing liquidity through such systems.

Key Insights Table

AspectDescription
What happenedAllbridge Core paused after a flash-loan exploit drained roughly $1.65M from Solana liquidity pools.
Attack methodAttacker used a $1.12M flash loan to manipulate USDC/USDT pool ratios, enabling favorable withdrawals.
Immediate responseProtocol pause, advisory for LPs to withdraw, and request for traders who benefited to return funds.
Funds movementStolen assets were bridged to Ethereum and dispersed across multiple addresses; recovery status uncertain.
Broader riskHighlights ongoing vulnerability of pool-based cross-chain mechanisms to flash-loan manipulation.
Last edited at:2026/7/20
#SOL#BNB#USDT#Ethereum#stablecoin

Mr. W

ZNews full-time writer