July 20, 2026 ChainGPT

Allbridge Core Paused After $1.65M Solana Flash-Loan Exploit Drains Stablecoin Pools

Allbridge Core Paused After $1.65M Solana Flash-Loan Exploit Drains Stablecoin Pools
Allbridge, a cross-chain bridge that moves native assets between blockchains, has paused its Core protocol after an attacker siphoned roughly $1.65 million from its Solana liquidity pools in a flash‑loan exploit, according to the project and blockchain security firms. What happened - The incident, disclosed by Allbridge on July 19–20, 2026, targeted Allbridge Core, which relies on pools of native stablecoins (USDC, USDT) rather than minting wrapped tokens. The team said it “paused the protocol as a precaution” and urged liquidity providers to withdraw funds from affected pools. - Security firm PeckShield pegged the loss at about $1.65 million and reported that the stolen funds were bridged from Solana to an Ethereum address (0x651591b68A9c9650FB23F642162353306281ffDe) before being dispersed. - CertiK’s analysis detailed the attack flow: the exploiter took a roughly $1.12 million flash loan from Solana lending protocol Kamino, then executed a rapid sequence of stablecoin swaps that distorted Allbridge’s internal pool accounting. That mispricing allowed the attacker to swap a few thousand dollars of USDT for about $2.24 million in USDC, which was then bridged to Ethereum and distributed across other addresses. Why it worked - The flash loan enabled a large, temporary on‑chain position without upfront capital; the attacker used that leverage to manipulate the pricing mechanism Allbridge uses to value its pools, creating a “temporary positive arbitrage window” where mispriced assets could be converted at a profit. - Allbridge says the imbalance briefly opened the door for other traders to buy the mispriced assets. The team publicly appealed to anyone who profited from that arbitrage to return the proceeds to a designated address so funds can be used to compensate affected liquidity providers. Response and status - Allbridge said it is preparing a detailed post‑mortem and that there is “no threat to users’ liquidity right now” as it works to relaunch Core without liquidity pools. The protocol remains paused while investigators trace the bridged funds and assess recoverability. - It isn’t yet clear how much of the $1.65 million remains recoverable. Context and history - This is not Allbridge’s first flash‑loan setback: in April 2023 a similar exploit drained roughly $573,000 from its BNB Chain pools; that incident led the team to recover most funds and change how it calculates liquidity and withdrawals. - Allbridge raised $2 million in 2022 to expand the bridge and fund security audits, but cross‑chain bridges and their underlying liquidity pools remain prime targets in DeFi. - More than $840 million was lost to DeFi hacks in the first five months of 2026, and recent large bridge incidents include a $4.67 million drain from an Axelar–Secret Network bridge due to an “infinite mint” bug. What’s next - Recovery will depend on successful tracing of the bridged funds and on whether parties who profited from the transient arbitrage return assets to the designated address. Allbridge’s forthcoming breakdown should clarify technical details and next steps for affected LPs and users. Read more AI-generated news on: undefined/news