Allbridge Core paused its cross-chain stablecoin protocol after an attacker manipulated its Solana liquidity pools, with PeckShield estimating losses at about $1.65 million.
The attack began with a $1.12 million USDC flash loan from Kamino Finance. The borrowed capital funded rapid swaps between USDC and USDT, pushing Allbridge Core’s internal pool ratios away from the stablecoins’ market values. The attacker then withdrew liquidity at the distorted exchange rate and repaid the Kamino loan within the same transaction.
Onchain Lens traced more than $1.1 million in proceeds from the transaction. The difference between that figure and PeckShield’s $1.65 million estimate has not been reconciled through an Allbridge postmortem, leaving the protocol’s final loss and the attacker’s net profit subject to revision.
The exploit targeted Allbridge Core’s native-liquidity model, which uses stablecoin pools across supported blockchains rather than minting wrapped assets. Large swaps can change the rate offered by an imbalanced pool, creating better pricing for transfers that return liquidity to the depleted side. The attacker used flash-loan capital to force that mechanism into an extreme state before extracting value.
Protocol Paused As Funds Move To Ethereum
Allbridge paused the protocol while its team investigated the affected pools. Liquidity providers were told to withdraw their positions, although the project did not immediately identify every pool exposed to the attack.
The pool imbalance also opened a temporary arbitrage window for other traders. Allbridge asked users who captured gains from the abnormal pricing to return the funds, with recovered assets earmarked for compensating affected liquidity providers.
PeckShield tracked the attacker’s proceeds from Solana to Ethereum. A separate onchain trace found that roughly $1.1 million was subsequently routed through privacy infrastructure, complicating attempts to follow the assets beyond their initial cross-chain movement.
The drain follows a $1.34 million loss from Raydium’s legacy Solana pools, where dormant liquidity remained exposed through deprecated code. Cross-chain infrastructure has faced heavier losses, with bridge-related exploits reaching an estimated $328.6 million by mid-May.
Allbridge Faces Second Pool-Manipulation Exploit
Allbridge suffered a similar flash-loan attack in April 2023, when manipulated pricing in its BNB Chain pools produced losses of about $573,000 in BUSD and USDT. The attacker acted as both a liquidity provider and swapper, changing the pool balance before withdrawing assets at an artificial rate.
Allbridge had not published a technical postmortem, confirmed the final affected balance or detailed its compensation process at publication. Allbridge Core remained paused while liquidity providers were directed to remove funds from affected pools.



Be the first to comment