Article is online

Allbridge Halts Core Protocol After $1.65M Flash-Loan Exploit Drains Solana Pools

Allbridge Halts Core Protocol After $1.65M Flash-Loan Exploit Drains Solana Pools

Table of Contents




You might want to know


How did a flash loan enable the attacker to extract roughly $1.65 million from Allbridge's Solana stablecoin pools?


What steps has Allbridge taken to protect users and recover funds after the exploit?



Main Topic


Cross-chain bridge Allbridge announced a precautionary pause of its Core protocol after an attacker drained approximately $1.65 million from its Solana stablecoin liquidity pools. The incident was reported by multiple blockchain security firms and confirmed by the project. Allbridge Core uses pools of native stablecoins—such as USDC and USDT—rather than issuing wrapped tokens, and the attacker exploited the pools' internal pricing during a short, high-value transaction sequence.



According to security analyses, the exploit began with a flash loan of about $1.12 million taken from a Solana lending protocol. The attacker executed a rapid sequence of stablecoin swaps that deliberately distorted the pool accounting used by Allbridge to price assets. That distortion created a momentary pricing imbalance across pools, allowing the attacker to swap a relatively small amount of one stablecoin into roughly $2.24 million worth of another, then bridge the proceeds to Ethereum and disperse the funds across several addresses.



The manipulation also left Allbridge's pools out of balance, opening a temporary positive arbitrage opportunity that other traders could have exploited. In response, Allbridge urged liquidity providers to withdraw funds from affected pools and asked anyone who profited from the transient arbitrage to return gains to a designated address so those proceeds could be used to compensate impacted liquidity providers. The team stated it is preparing a post-mortem and emphasized there is currently "no threat to users' liquidity" as it works to relaunch Core without the affected pool model.



This is not the first flash-loan incident affecting Allbridge. In April 2023, a flash-loan style exploit removed around $573,000 from its BNB Chain pools. After that event, the project recovered most funds and adjusted liquidity and withdrawal calculations. Despite corrective actions, cross-chain bridges and the liquidity pools they rely on remain frequent targets for attackers because they mediate high-value transfers across ecosystems that lack native interoperability.



Industry observers note that the broader DeFi sector has experienced significant losses from hacks, with hundreds of millions lost in early 2026 and recurring large-scale incidents on cross-chain systems. The ability to trace bridged funds and the cooperation of arbitrageurs who may have profited from imbalances will materially affect how much of the stolen $1.65 million can be recovered. Allbridge's public communications indicate work is underway to trace and, where possible, reclaim funds, but the outcome depends on blockchain forensics and the behavior of those who received bridged assets.



Allbridge has committed to publishing a detailed breakdown and post-mortem once investigations progress. In the meantime, the protocol remains paused and liquidity providers have been advised to withdraw from affected pools. The project reiterated that recovered funds will be used to compensate affected liquidity providers, and it appears focused on relaunching Core with modified mechanisms to reduce reliance on vulnerable pool accounting.



Key Insights Table































Aspect Description
Attack Vector A flash loan (~$1.12M) was used to manipulate stablecoin swap pricing within Allbridge's Solana pools.
Loss Amount Approximately $1.65 million was withdrawn and bridged from Solana to Ethereum.
Immediate Response Allbridge paused the Core protocol, advised LPs to withdraw, and requested return of arbitrage gains.
Recovery Prospects Tracing bridged funds and cooperation from arbitrageurs will determine recoverable amounts.
Context Bridges and liquidity pools are recurring targets in DeFi; similar incidents affected Allbridge in 2023.


Afterwards...


Looking forward, the Allbridge incident reinforces several priorities for the cross-chain and DeFi communities. Continued investment in on-chain forensics and real-time monitoring can improve the speed and effectiveness of incident response. Research into more robust pool pricing mechanisms, flash-loan resistant designs, and formal verification of critical protocol components could reduce the attack surface for similar exploits. Coordination between bridges, analytics firms, and exchanges also matters for tracing and freezing illicit flows across chains.



Governance transparency and pre-funded insurance or compensation mechanisms may increase user confidence when incidents occur. Equally important is ongoing security auditing, timely disclosure of root causes, and iterative protocol hardening informed by previous attacks. Collectively, these measures can help limit the frequency and impact of high-value cross-chain exploits while enabling safer interoperability between blockchains.


Last edited at:2026/7/20
#SOL#BNB#Defi#Ethereum#stablecoin

數字匠人

Idle Passerby