Allbridge Cross-Chain Bridge Exploited for $1.65M in Flash Loan Attack

2026-07-22
Allbridge Cross-Chain Bridge Exploited for $1.65M in Flash Loan Attack

Allbridge Core has reportedly suffered a major security incident after an attacker drained approximately $1.65 million from its Solana based liquidity pools. 

The incident involved a flash loan that was reportedly used to manipulate the balance and pricing dynamics of stablecoin pools before funds were extracted. 

Allbridge paused the affected protocol following the attack and urged liquidity providers to withdraw their funds. Security firms including PeckShield and CertiK also reported that the stolen assets were subsequently moved from Solana to Ethereum.

Key Takeaways

  • Allbridge Core reportedly lost around $1.65 million in a flash loan driven exploit targeting Solana liquidity pools.

  • The attacker reportedly manipulated pool ratios before withdrawing assets at favourable rates and repaying the flash loan.

  • The stolen funds were reportedly bridged from Solana to Ethereum, highlighting the wider security challenges facing cross chain infrastructure.

What Happened in the Allbridge Flash Loan Attack?

Allbridge Cross-Chain Bridge Exploited for $1.65M in Flash Loan Attack

source by AI Illustration

The Allbridge incident highlights how sophisticated attacks can exploit the mechanics of decentralised finance without necessarily relying on a straightforward coding error.

According to blockchain analysts cited in reports, the attacker used a flash loan of approximately $1.12 million from Kamino, a Solana based liquidity protocol. 

The borrowed funds were reportedly used to conduct rapid swaps involving USDC and USDT, creating an imbalance in the affected Allbridge liquidity pools.

The key feature of a flash loan is that the borrowed funds can be obtained and repaid within the same transaction, provided the transaction meets the lender's conditions. This allows an attacker to temporarily access a very large amount of capital without providing traditional collateral.

In this case, the reported strategy appears to have involved using that temporary capital to distort the internal balance of a stablecoin pool. Once the pool became imbalanced, the attacker was reportedly able to withdraw assets at an advantageous rate.

After extracting the value, the attacker repaid the flash loan and retained the remaining proceeds as profit.

Reports have placed the total loss at approximately $1.65 million, although some coverage has rounded the figure slightly higher to around $1.66 million. The precise amount may become clearer when a full technical investigation is published.

Read Also: Solana Price Today: SOL to USD Live

join bitrue to get 938 usdt

A Pool Manipulation Attack Rather Than a Traditional Bug

One important aspect of the incident is that the attack has been described as a form of pool manipulation.

That distinction matters because not every DeFi exploit involves an obvious programming vulnerability such as a faulty smart contract function or a compromised private key. 

Some attacks instead take advantage of how a protocol calculates prices, values liquidity or accounts for assets when the underlying pool becomes temporarily unbalanced.

When a protocol relies on liquidity pools to facilitate transactions, sudden and unusually large trades can potentially create conditions that would not normally occur during regular market activity. 

If the protocol's accounting mechanisms do not adequately protect against these temporary distortions, an attacker may be able to extract value before the pool returns to normal conditions.

The reported Allbridge attack appears to fit this broader pattern, with the flash loan providing the capital needed to create the temporary imbalance.

Read Also: SOL Staking: Earn SOLANA Rewards

Why the $1.65 Million Allbridge Exploit Matters for DeFi

The immediate financial loss is significant, but the wider implications may be even more important for the decentralised finance sector.

Cross chain bridges are among the most technically complicated parts of the crypto ecosystem. Their purpose is to allow assets and liquidity to move between different blockchain networks, each with its own infrastructure and technical design.

This creates additional layers of risk.

A bridge must not only manage liquidity but also maintain accurate accounting across different networks. Depending on its architecture, it may need to handle smart contracts, liquidity providers, price calculations, messaging systems and settlement mechanisms.

Any weakness in one part of that system can potentially have consequences for users and liquidity providers.

The Allbridge incident demonstrates another risk associated with liquidity based bridge designs. Even when the assets involved are stablecoins, the underlying pool can potentially become vulnerable if an attacker has enough capital to create a temporary imbalance.

Flash loans make this particularly challenging because they remove one of the traditional barriers faced by attackers: access to capital.

An individual may not have $1 million or more available to execute a large market manipulation strategy. A flash loan, however, can provide access to substantial capital for a very short period, provided the loan is repaid within the same transaction.

That means the real security question is not simply whether a protocol has enough liquidity. It is whether its pricing and accounting mechanisms remain robust when faced with extreme, temporary trading activity.

The incident is therefore a reminder that DeFi security requires more than auditing smart contract code. Protocol designers must also consider economic attacks, liquidity risks and unusual market conditions.

Read Also: How to Buy Solana (SOL) Safely in 2026

Stolen Funds Moved From Solana to Ethereum

Another important element of the Allbridge incident is what reportedly happened after the initial exploit.

Security firms including PeckShield and CertiK flagged that the stolen funds were moved from Solana to Ethereum. 

Reports also indicated that the assets were subsequently distributed across additional addresses, with some coverage stating that privacy related protocols were used to make tracing more difficult.

Moving assets across blockchain networks is not unusual in the crypto sector. However, it can complicate investigations because funds may quickly move between different ecosystems, wallets and services.

Blockchain transactions remain publicly visible, but following funds across multiple networks can require specialised monitoring tools and detailed on chain analysis.

The movement of the stolen assets also underlines the double edged nature of cross chain technology. Bridges are designed to improve interoperability and make it easier for users to move assets between networks. 

The same infrastructure can, however, potentially be used by attackers seeking to move illicitly obtained funds.

Read Also: SOL to USD – Convert Solana to USD (Real-time Calculator)

Allbridge Pauses the Protocol

Following the incident, Allbridge reportedly paused its Core protocol and advised liquidity providers connected to affected pools to withdraw their funds.

The team also reportedly asked users who benefited from the resulting pool imbalance to consider returning those funds, with the stated aim of helping compensate affected liquidity providers.

In a subsequent update, Allbridge said it was preparing a full report on the incident. The project also indicated that its newer Allbridge Next infrastructure was operating normally and that the incident would accelerate its transition away from the current Core and Classic systems.

The project has also reportedly discussed rebuilding Core without liquidity pools, instead using infrastructure involving CCTP and LayerZero. 

Such a redesign could potentially reduce exposure to the specific pool imbalance mechanism involved in the latest incident, although the effectiveness of any future architecture will depend on its implementation and security review.

The incident is also particularly notable because it follows an earlier flash loan attack affecting Allbridge's BNB Chain pools in 2023. 

Reports have described the latest event as the protocol's second flash loan attack, making the response and any architectural changes especially important for the project's future.

Read Also: SOL/USDT Perpetual Futures

TradeFi Bitrue

Conclusion

The $1.65 million Allbridge exploit is another reminder that crypto users need to consider security alongside potential returns. 

The incident reportedly involved flash loan driven pool manipulation rather than a simple contract bug, showing how complex DeFi risks can be. 

Cross chain bridges remain useful infrastructure, but users should understand the risks associated with liquidity pools and smart contract based systems before committing funds. 

For traders looking for a more convenient way to access the crypto market, Bitrue provides a platform for buying and trading digital assets with security features designed to support a safer trading experience. Always research the risks and manage your funds carefully before trading.

FAQ

What happened to Allbridge Core?

Allbridge Core reportedly suffered an exploit that drained approximately $1.65 million from its Solana based liquidity pools. The protocol was subsequently paused while the incident was investigated.

How did the Allbridge flash loan attack work?

Reports indicate that the attacker used a large flash loan to conduct rapid swaps and manipulate the ratios of stablecoin liquidity pools. The attacker then reportedly withdrew assets at favourable rates before repaying the flash loan.

How much money was stolen from Allbridge?

The reported loss is approximately $1.65 million, although some reports have rounded the figure to around $1.66 million. The exact amount may be clarified in the project's full incident report.

Where did the stolen Allbridge funds go?

Security firms reported that the stolen assets were moved from Solana to Ethereum. Further movements across addresses were also reported as investigators tracked the funds.

Is Allbridge still operating after the exploit?

Allbridge paused its Core protocol following the incident. The team has reportedly been working on its transition towards newer infrastructure, while stating that Allbridge Next was operating normally.

Disclaimer: The views expressed belong exclusively to the author and do not reflect the views of this platform. This platform and its affiliates disclaim any responsibility for the accuracy or suitability of the information provided. It is for informational purposes only and not intended as financial or investment advice.

Disclaimer: The content of this article does not constitute financial or investment advice.

Register now to claim a 186 USDT newcomer's gift package

Join Bitrue for exclusive rewards

Register Now
register

Recommended

Bank of Korea Prepares Live CBDC Transactions With Nine Banks
Bank of Korea Prepares Live CBDC Transactions With Nine Banks

The Bank of Korea is moving its CBDC pilot towards live transaction testing in September, expanding Project Hangang to nine participating banks. The initiative will use central bank infrastructure alongside bank issued deposit tokens to explore real payments, peer to peer transfers and government subsidy distribution.

2026-07-22Read