Allbridge, the firm behind the cross-chain stablecoin bridge Allbridge Core, has paused its protocol after a reported security incident on Sunday that investigators and on-chain analysts say resulted in roughly $1.65 million being drained. The company said the pause is a precaution while it investigates, and it urged users with liquidity in impacted pools to withdraw.
According to Allbridge Core’s own announcement on X, the exploit affected Allbridge Core’s deployment on Solana. Monitoring accounts cited in the incident also claim the attacker moved funds from Solana to Ethereum and then funneled proceeds into privacy-related pools, illustrating how quickly bridge exploits can turn into multi-chain extraction events.
Key takeaways
- Allbridge Core has paused its protocol following a reported cross-chain stablecoin bridge incident affecting its Solana deployment.
- The incident reportedly involved ~$1.65 million drained, with on-chain monitoring suggesting the attacker bridged funds from Solana to Ethereum.
- Liquidity providers were urged to withdraw from affected pools to limit exposure while the team investigates.
- On-chain analysis points to a flash-loan and rate-manipulation pattern that allowed the attacker to profit from a temporary pool imbalance.
- Bridge exploits are recurring: multiple reported attacks have hit different bridge systems since May, highlighting structural risk across the sector.
Allbridge Core pauses after Sunday incident
Allbridge said in a Sunday post on X that Allbridge Core was “experiencing a security incident” and that it had paused the protocol while it investigates. The firm added a direct instruction to users: if they have liquidity in affected pools, they should withdraw immediately.
The breach was reported to involve Allbridge Core’s Solana deployment. CertiKAlert later posted that the stolen funds had already been bridged from Solana to Ethereum before moving into privacy pools, according to the monitoring thread referenced by reporting shared on social media.
While the company did not provide additional technical details in the initial communication, the operational response—pausing the protocol and prompting LP withdrawals—suggests that Allbridge recognized ongoing risk rather than treating the event as a fully contained, already-resolved failure.
What on-chain reports say happened
On-chain analytics highlighted a specific mechanism consistent with recent DeFi bridge exploitation patterns. According to Onchain Lens, the attacker made a $1.12 million USDC flash loan from Kamino. The attacker then used rapid USDC/USDT swaps to distort the exchange rate inside the Allbridge Core stablecoin pool.
The same reporting indicates the attacker took advantage of the manipulated pricing by withdrawing liquidity at unfavorable-to-others rates. After extracting the difference created by the temporary imbalance, the attacker reportedly repaid the flash loan and retained the profit from the rate disruption.
Allbridge Core’s own follow-up language, as reflected in the incident discussion, referenced a “pool imbalance” that created a “temporary positive arbitrage window.” The company also suggested that if anyone took advantage of the window, they should consider returning funds, with any returned amounts intended to support compensation for affected liquidity providers.
Why this kind of bridge attack keeps repeating
This incident did not occur in isolation. The reporting notes that it is at least the sixth attack targeting a cross-chain bridge since May. Bridges are frequently attacked because they manage large pools of assets across networks—assets that back bridged tokens on the destination chain. If an attacker can manipulate pricing, liquidity, or settlement logic, the bridge’s pooled reserves can amplify losses.
In practice, these attacks often combine speed (to exploit temporary state changes) with cross-chain movement (to break the attacker’s funds away from any single environment). Sunday’s event appears to align with that playbook: on-chain monitoring suggested stolen value moved from Solana to Ethereum before being moved into privacy pools, underscoring the challenge for recovery once funds change hands across chains.
The case also highlights a persistent tension for investors and LPs: even when bridge designs rely on liquidity pools and token accounting rather than direct custodian control, attackers can still reach profit by exploiting assumptions around swap paths, price discovery, and pool invariants—especially when flash loans are available.
Allbridge Core isn’t new to flash-loan style exploits
Allbridge Core’s Sunday incident is not the company’s first exposure to flash-loan-driven manipulation. Earlier coverage and related documentation indicate that in April 2023 Allbridge was exploited for about $573,000 through a flash loan attack on Allbridge’s pool on BNB Chain.
That earlier event, as described in an analysis of the hack, involved an attacker acting as both liquidity provider and swapper, exploiting a flaw in smart contract logic that allowed them to manipulate swap prices. The outcome included drains denominated in BUSD and USDt, totaling roughly $573,000 based on the figures cited in the underlying analysis.
With Sunday’s report pointing to a similar exploitation pattern—flash loan funding, fast swaps, pool imbalance, then liquidity withdrawals—the renewed incident raises a practical question for LPs: even if a team responds by pausing the protocol, what controls exist to prevent the same class of risk from reappearing under different market conditions or on different deployments?
Cross-chain bridge attacks remain a sector-wide problem
Broader reporting shows that cross-chain bridges have faced repeated pressure from exploits across multiple ecosystems in recent months. In June, for example, Taiko urged users to withdraw assets from its bridges after a $1.7 million exploit, later reopening its bridge 11 days after completing a recovery plan. Weeks earlier, Secret Network was reportedly exploited through an “infinite mint” bug that created unbacked versions of Axelar-wrapped assets, resulting in a $4.67 million incident. Other widely reported bridge failures included Gravity Bridge, Verus Bridge, and Butter Network.
Together, these cases reinforce an important takeaway for anyone using or providing liquidity to bridge-related systems: cross-chain infrastructure concentrates both technical complexity and financial value, and the attack surface expands as protocols integrate multiple chains, wallets, swap venues, and liquidity mechanisms.
Readers should watch closely for two things next: whether Allbridge Core can determine the full scope of the impacted liquidity pools on Solana and any related deployments, and whether the team’s investigation leads to specific changes that reduce the likelihood of similar flash-loan-driven pool imbalances recurring.





Be the first to comment