July 21, 2026 ChainGPT

Allbridge Pauses Core After $1.65M Flash-Loan Drains Solana USDC/USDT Pools

Allbridge Pauses Core After $1.65M Flash-Loan Drains Solana USDC/USDT Pools
Allbridge, a cross-chain bridge that moves native assets between blockchains, has paused its Core protocol after a flash-loan exploit drained roughly $1.65 million from its Solana liquidity pools, security firms and the project said. What happened - On July 19 Allbridge halted Core “as a precaution” and urged liquidity providers in the affected pools to withdraw funds while it investigates. The team said it is preparing a full post-mortem and insisted there is “no threat to users’ liquidity right now” as it works to relaunch Core without pool-based liquidity. - Blockchain security firms pegged the loss at about $1.65M. PeckShield initially reported the figure, and CertiK provided a technical breakdown of the exploit. How the attacker pulled it off - The attacker took a Solana flash loan of about $1.12M from lending protocol Kamino, then executed a rapid series of stablecoin swaps inside Allbridge’s native stablecoin pools (USDC/USDT). - Those swaps distorted the pools’ internal accounting and left them mispriced. Using only a few thousand dollars of USDT, the attacker was able to extract roughly $2.24M in USDC before bridging the proceeds to Ethereum and dispersing them across addresses (one destination reported: 0x651591b68A9c9650FB23F642162353306281ffDe). - The manipulation also created a “temporary positive arbitrage window” that let other traders buy mispriced assets. Allbridge publicly asked anyone who profited from that window to return gains to a designated address so proceeds can be used to compensate affected liquidity providers. Context and fallout - This is not Allbridge’s first flash-loan incident. In April 2023 a flash-loan exploit siphoned about $573K from its BNB Chain pools; Allbridge later said it recovered most of those funds and adjusted how it calculates liquidity and withdrawals. - Allbridge raised $2M in 2022 to expand the bridge and fund security audits, but cross-chain bridges and their liquidity pools remain prime targets. DeFi losses have surged in 2026—more than $840M was lost to DeFi hacks in the first five months of the year—while a July incident drained $4.67M from an Axelar–Secret Network bridge exploiting an “infinite mint” token bug. What’s next - The protocol remains paused. Tracing and clawing back the bridged funds will determine how much can be recovered, and recovery will also depend on whether arbitrageurs return profits as requested. - Allbridge says it aims to return all affected funds and is working on fixes and a relaunch strategy for Core that avoids the vulnerable pool design. This incident is another reminder that pool-based pricing mechanisms and cross-chain routing remain attack vectors in DeFi. Users with exposure to Allbridge pools should follow the project’s announcements and withdraw liquidity if instructed. Read more AI-generated news on: undefined/news