Allbridge Pauses Cross-Chain Bridge After $1.65 Million Exploit

Ledger
Bitbuy


Allbridge paused its Core cross-chain bridge protocol on July 20, 2026, after an attacker drained roughly $1.65 million from its Solana deployment using a flash loan to manipulate the pool’s exchange rate.

What Happened to Allbridge

The hack was first flagged by Lookonchain on the social media platform X, wherein the attacker took a $1.12 million USDC flash loan from the lending protocol Kamino, then executed rapid USDC/USDT swaps to distort the exchange rate within Allbridge Core’s stablecoin pool. With the rate manipulated, the attacker withdrew liquidity at the skewed price, repaid the original $1.12 million loan, and kept the difference.

Allbridge confirmed the incident in a post on X, writing: “Allbridge Core is experiencing a security incident. We have paused the protocol as a precaution while we investigate. If you have liquidity in affected pools, please withdraw now.” 

The company also acknowledged the exploit created a temporary arbitrage window, adding, “If you took advantage of it, please consider returning funds… this will go directly toward compensating affected LPs.”

okex

This is not Allbridge’s first flash loan incident. In April 2023, an attacker exploited a smart contract flaw in Allbridge’s BNB Chain pool for $573,000, split between roughly $289,900 in BUSD and $290,900 in USDT. 

Allbridge recovered about $465,000 of that earlier theft through a white-hat hacker arrangement, though this recovery is not independently corroborated by the other sources reviewed for this piece. Separately, Allbridge integrated with Algorand in January 2026, expanding its cross-chain stablecoin capabilities shortly before this latest incident.

The Bigger Picture

Leading independent digital media platform Cointelegraph had counted this as at least the sixth cross-chain bridge exploit since May.

Part of this pattern that includes Taiko’s Ethereum layer-2 bridge, which lost $1.7 million in June before reopening 11 days later following a four-step recovery plan, and Secret Network, which lost $4.67 million to an “infinite mint” bug that created unbacked versions of Axelar-wrapped assets. Moreover, Gravity Bridge, Verus Bridge, and the Butter Network have also been targeted in recent months, along with Kelp DAO’s LayerZero-powered bridge, which lost $292 million in a single exploit in April 2026.

For broader context on how DeFi platforms manage this kind of risk, our coverage of DeFi adoption growth tracks related security and infrastructure trends, and our crypto scams to avoid guide covers patterns worth watching across the space generally.

What Comes Next

Whether Allbridge can recover funds spanning two blockchain ecosystems, as it partially did after its 2023 incident, remains the key situation to watch. On-chain intelligence platforms are likely keeping track of the attacker’s wallet, and any movement toward centralized exchange deposit addresses could signal whether a freeze or recovery becomes possible.

What this means for you: if you have liquidity in Allbridge Core’s affected pools, Allbridge has advised withdrawing now while the investigation continues. This incident likely takes us back to bridges that hold pooled funds backing assets on destination chains, which remain a recurring target for exploits across the industry.





Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*