July 20, 2026 ChainGPT

Allbridge Core Pauses After ~$1.65M Solana Flash-Loan Exploit — Users Urged to Withdraw

Allbridge Core Pauses After ~$1.65M Solana Flash-Loan Exploit — Users Urged to Withdraw
Allbridge Core paused after roughly $1.65M Solana exploit Allbridge Core has paused its cross-chain stablecoin protocol following a security incident on Solana that on-chain security firm PeckShield values at about $1.65 million. The team has urged users with funds in the affected liquidity pools to withdraw immediately while it investigates. What happened - Onchain analytics group Onchain Lens says the attacker used a $1.12 million USDC flash loan from Kamino to manipulate the USDC/USDT liquidity pool on Allbridge Core. - According to Onchain Lens, the attacker executed rapid swaps to skew the pool’s token ratio, then withdrew liquidity at the distorted price and repaid the flash loan within the same transaction. Onchain Lens reported more than $1.1 million was extracted; PeckShield’s broader estimate is roughly $1.65 million. - PeckShield also reported that the stolen funds were bridged off Solana to Ethereum. Protocol response - Allbridge Core posted a public notice: “Allbridge Core is experiencing a security incident. We have paused the protocol as a precaution while we investigate. If you have liquidity in affected pools, please withdraw now.” - The project said the attack left some pools temporarily out of balance, creating a short-lived positive arbitrage window that allowed traders to profit from abnormal pricing. Allbridge asked anyone who profited to consider returning funds to a recovery address; returned assets would be used to reimburse affected liquidity providers. - The team has not given a reopening date or published a technical postmortem as of this writing. Technical context - Flash loans enable borrowing and repaying funds within a single blockchain transaction without collateral. In this case, investigators say the flash loan itself was not the vulnerability; rather, the borrowed capital let the attacker shift the pool ratio enough to extract value before the transaction closed. - After the exploit, the attacker reportedly moved proceeds from Solana to Ethereum, complicating recovery efforts. Background and wider trend - This is not Allbridge’s first incident: in April 2023 an attacker manipulated swap pricing on a BNB Chain pool, costing about $573,000; Allbridge later recovered roughly $465,000 after offering a white-hat-style reward. - The exploit follows a string of recent cross-chain incidents. In May, the Verus–Ethereum bridge lost over $11.5 million in an attack tied to missing validation checks; Transit Finance also suffered a roughly $1.88 million loss in another cross-chain breach. Allbridge has not yet indicated whether the Solana incident shares technical similarities with previous attacks. The investigation is ongoing; users with exposure to the affected pools should withdraw immediately and monitor official Allbridge channels for updates. Read more AI-generated news on: undefined/news