Allbridge, the company behind the cross-chain stablecoin bridge Allbridge Core, has temporarily paused the protocol after a reported security incident drained $1.65 million on Sunday. The disruption specifically impacted Allbridge Core’s Solana deployment, while the attacker reportedly moved the stolen funds onward to Ethereum and then into privacy-oriented pools.
In a post on X, Allbridge said it paused the protocol “as a precaution” while it investigates and urged users to withdraw liquidity from any affected pools. The episode adds to a growing list of cross-chain bridge exploits earlier this year, highlighting how attackers continue to target bridge-controlled liquidity that can become valuable once manipulated.
Key takeaways
- Allbridge Core paused operations after a $1.65 million reported incident affecting its Solana deployment.
- The attacker allegedly bridged funds from Solana to Ethereum before moving them into privacy pools, according to monitoring reports shared on X.
- Onchain analysis reported the use of a $1.12 million USDC flash loan to distort stablecoin pool pricing.
- Allbridge previously faced a flash-loan related exploit on BNB Chain in 2023, underscoring a recurring risk pattern in bridge liquidity pools.
- This incident follows multiple bridge attacks since May, reinforcing that cross-chain liquidity remains a persistent target for criminals.
Protocol pause after Solana-to-Ethereum theft
Allbridge Core’s pause was prompted by what the company described as a “security incident.” According to Allbridge’s statement on X, the protocol was stopped as a precaution while the team investigates and assesses exposure.
The company specifically advised: if users have liquidity in impacted pools, they should withdraw. That kind of guidance is typical after bridge-related exploits because the attacker’s impact can extend beyond the initial theft—particularly if pool pricing was manipulated and remaining liquidity becomes temporarily mispriced.
Monitoring information shared publicly points to a fast-moving sequence. An alert posted by CertiKAlert indicated the funds were already bridged from Solana to Ethereum after the incident, before the attacker reportedly routed value into privacy pools.
How the attacker reportedly manipulated stablecoin liquidity
Onchain Lens reported a detailed mechanism behind the event: the attacker allegedly took a $1.12 million USDC flash loan from Kamino, then executed rapid USDC/USDT swaps that disrupted the Allbridge Core stablecoin pool’s exchange rate.
Those trades reportedly created a window where the pool imbalance could be exploited. The attacker then withdrew liquidity at rates distorted by the manipulation, repaying the original flash loan and keeping the difference between what was withdrawn and what was effectively required to settle the loan.
Allbridge later referred to the outcome in its own communications. The company said the “pool imbalance created a temporary positive arbitrage window” and added that anyone who benefited should consider returning funds. It also stated returned value would go toward compensating affected liquidity providers.
For investors and traders, the practical takeaway is that bridge exploits are not only about the amount ultimately stolen. Price distortion and temporary arbitrage dynamics can lead to secondary effects—such as losses for liquidity providers who remain exposed after the initial manipulation, unless the protocol is paused and withdrawal guidance is followed.
A flash-loan pattern tied to recurring bridge vulnerabilities
This was not the first time Allbridge Core faced flash-loan style pressure. The company and its infrastructure have been hit before: in April 2023, Allbridge was exploited on the BNB Chain via a flash loan against a pool there, according to a technical analysis published by SolidityScan.
That earlier incident reportedly involved an attacker acting as both liquidity provider and swapper while exploiting business logic in a smart contract. The mechanism allowed the attacker to manipulate swap prices, which led to reported drains of $289,900 in BUSD and $290,900 in USDt.
While each bridge deployment and asset routing can differ, the continuity in tactics—flash loans combined with liquidity pool price manipulation—signals a broader vulnerability class. In many cross-chain designs, bridges rely on liquidity pools to support issuance and redemption of bridged assets. If pool accounting and swap logic can be influenced within a single transaction sequence, attackers may generate profit without needing long-term capital exposure.
The near-term uncertainty for users is how thoroughly Allbridge Core investigated the precise smart contract paths involved on Solana and whether any additional pools—or liquidity routes—were affected beyond the reported $1.65 million figure.
Cross-chain bridges targeted since May
This Allbridge Core incident lands in the middle of a broader streak of reported bridge attacks. Earlier coverage from Cointelegraph detailed how multiple protocols urged user withdrawals or paused bridge services following exploits, reflecting how quickly damage can spread when attackers identify liquidity weaknesses.
In June, Cointelegraph reported that Taiko, an Ethereum layer-2 network, urged users to withdraw assets after attackers exploited one of its bridge protocols and stole $1.7 million. Taiko later reopened its bridge 11 days later after completing a four-step recovery plan.
Weeks before that, Cointelegraph reported that Secret Network was exploited via an “infinite mint” bug in a vulnerable smart contract. That incident reportedly resulted in $4.67 million in unbacked Axelar-wrapped assets.
Other bridge failures mentioned in recent reporting include Cointelegraph’s reports on the Gravity Bridge halting after a reported $54 million exploit, the Verus Bridge reportedly being exploited for millions, and Butter Network losing most of its value after a reported quadrillion token mint exploit.
Taken together, the pattern is consistent: bridge systems concentrate liquidity, and that liquidity often translates into high payoff for attackers who can manipulate pricing, mint/burn mechanics, or settlement logic across chains. When protocols respond with pauses and user-withdrawal instructions, they are effectively trying to limit further exposure while remediation work is underway.
For users, the next watchpoints are straightforward: whether Allbridge Core confirms the full scope of affected pools, when the protocol restarts (if it does), and what safeguards are described in the aftermath—especially around pool invariants and flash-loan-resistance. Until those details are clear, liquidity providers should assume that temporary pricing distortions may not fully resolve without an operational pause.





Be the first to comment