News
Platform news and market context
News
Platform news and market context
Allbridge Halts Cross-Chain Bridge Operations Following $1.65M Exploit
Allbridge has suspended its Allbridge Core protocol after a security incident on Sunday resulted in a reported $1.65 million loss. An attacker allegedly manipulated stablecoin pool rates using a flash loan on the bridge's Solana deployment.

Allbridge, the firm responsible for the cross-chain stablecoin bridge Allbridge Core, has paused its protocol as a precaution after a "security incident" on Sunday reportedly led to a $1.65 million drain. The incident targeted the Solana deployment of Allbridge Core. The attacker subsequently bridged the stolen funds from Solana to Ethereum and then funneled them into privacy pools.
In a post on X on Sunday, the company announced, “Allbridge Core is experiencing a security incident.” The statement continued, “We have paused the protocol as a precaution while we investigate. If you have liquidity in affected pools, please withdraw now.”
This exploit marks at least the sixth attack directed at a cross-chain bridge since May. Such bridges present lucrative opportunities for attackers because they typically hold substantial pools of funds that back the bridged assets on their destination blockchains.
Attack Methodology
According to a report from Onchain Lens, the attacker initiated the exploit by obtaining a $1.12 million USDC flash loan from Kamino. This was followed by a series of rapid USDC/USDT swaps, which succeeded in distorting the exchange rate of Allbridge Core's stablecoin pool.
The perpetrator then extracted liquidity from the pool at the manipulated rates. After repaying the original $1.12 million USDC loan, the attacker was able to keep the remaining difference as profit.
In response to the exploit, Allbridge issued a statement addressing those who may have benefited from the market disruption. "The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage of it, please consider returning funds… this will go directly toward compensating affected LPs,” the company added.
A Pattern of Vulnerability
This is not the first time Allbridge Core has been targeted by a flash loan attack. In a previous incident in April 2023, the platform was exploited for $573,000. That attack was carried out on Allbridge’s BNB Chain pool and also involved a flash loan. In that case, the attacker operated simultaneously as a liquidity provider and a swapper, leveraging a flaw in a smart contract to manipulate swap prices. The exploit resulted in the theft of $289,900 in Binance USD (BUSD) and $290,900 in USDt (USDT).
Recent Bridge Exploits
The Allbridge incident is part of a wider trend of security breaches affecting blockchain bridges.
- Taiko: In June, the Ethereum layer-2 blockchain Taiko urged its user base to withdraw assets from its bridges after an attacker exploited one of its protocols and stole $1.7 million. Taiko was able to reopen its bridge 11 days later, following the execution of a four-step recovery plan.
- Secret Network: Just weeks before the Taiko event, Secret Network suffered a $4.67 million exploit. The attack was made possible by an “infinite mint” bug within a vulnerable smart contract, which allowed for the creation of unbacked versions of Axelar-wrapped assets.
- Other Incidents: Other recent bridge exploits have targeted networks including the Gravity Bridge, Verus Bridge, and the Butter Network.
Discussion about this post