In short
- Cross-chain bridge Allbridge has paused its Core protocol after an attacker stole about $1.65 million from its Solana stablecoin liquidity swimming pools.
- The attacker used a $1.12 million flash mortgage from lending protocol Kamino to skew the swimming pools’ inner pricing, then extracted property cheaply and bridged them to Ethereum.
- Allbridge informed liquidity suppliers to withdraw and requested merchants who profited from the ensuing imbalance to return funds.
Cross-chain bridge Allbridge has paused its protocol after an attacker drained roughly $1.65 million from its Solana liquidity swimming pools in a flash mortgage assault, based on blockchain safety corporations and the undertaking itself.
Allbridge lets customers transfer property between blockchains that do not natively talk, and its Core product makes use of swimming pools of native stablecoins reminiscent of USDC and USDT relatively than minting wrapped tokens. On Sunday, the staff mentioned it had “paused the protocol as a precaution” whereas investigating, and urged liquidity suppliers to tug funds from affected swimming pools.
In a follow-up tweet, Allbridge famous that its staff was “getting ready an in depth breakdown” and autopsy report, including that “There is no such thing as a risk to customers liquidity proper now” as it really works to relaunch Core with out liquidity swimming pools.
The way it occurred
Allbridge confirmed an earlier tweet from safety agency PeckShield placing the loss at round $1.65 million, which famous that the attacker had bridged the funds from Solana to Ethereum.
Fellow agency CertiK detailed the strategy, which noticed the attacker borrow $1.12 million via a flash mortgage from Solana lending protocol Kamino, earlier than operating a fast sequence of stablecoin swaps to distort the interior accounting that costs property in Allbridge’s swimming pools.
With the swimming pools mispriced, the attacker swapped a number of thousand {dollars} of USDT for about $2.24 million in USDC earlier than bridging the proceeds to an Ethereum tackle and scattering them throughout others. It is not clear how a lot stays inside attain.
The manipulation left Allbridge’s swimming pools lopsided, briefly letting different merchants purchase up the mispriced property—a “short-term constructive arbitrage window,” because the staff put it. The DeFi platform requested anybody who profited from that window to ship the cash to a delegated tackle, saying it might “go immediately towards compensating affected LPs.” Its “objective is to return all affected funds,” the staff added.
Not the primary time
It is the second time Allbridge has been caught this fashion. In April 2023, an analogous flash-loan exploit drained round $573,000 from its BNB Chain swimming pools; the undertaking later mentioned it recovered many of the funds and reworked the way it calculates liquidity and withdrawals. Allbridge raised $2 million in 2022 to develop the bridge and fund safety audits.
Bridges and the liquidity swimming pools that feed them have lengthy been amongst DeFi’s most-targeted infrastructure. Greater than $840 million was misplaced to DeFi hacks in simply the primary 5 months of 2026, with cross-chain techniques repeatedly producing a few of the largest single losses. Simply final month, a bridge between Axelar and Secret Community was drained of $4.67 million after attackers exploited an “infinite mint” bug in a customized token contract.
Allbridge’s protocol stays paused, and the way a lot of the $1.65 million may be clawed again will hinge on tracing the bridged funds—and on whether or not the arbitrage merchants it appealed to really ship the cash again.
Every day Debrief E-newsletter
Begin every single day with the highest information tales proper now, plus authentic options, a podcast, movies and extra.