The cross-chain bridge Allbridge Core paused operations on Sunday after someone drained $1.65 million from its pool on Solana. The company confirmed a "security incident" and urged users to withdraw liquidity from affected pools immediately while the investigation continues. If you hold assets in bridges between blockchains, this story is worth following, since these attacks keep happening more often, and this isn't even the first one for this particular protocol.
What happened to the Allbridge Core bridge?
Allbridge Core connects different blockchains and lets users move stablecoins between networks without a centralized exchange. A user deposits a token on one network and receives its equivalent on another. On Sunday the company posted on X that it had paused the protocol as a precaution while it checked the scale of the damage.
The attacker had already moved the stolen funds from Solana to Ethereum, then routed them into privacy pools, which mix transactions from many users and make the money harder to trace. According to the analytics platform Lookonchain, the attack hit specifically the Solana version of the protocol, not the other networks where Allbridge operates.
The team asked everyone holding liquidity in the affected pools to withdraw it right away. That's fairly standard for DeFi after a hack. The faster users pull their funds, the smaller the chance the attacker reaches them too. While the review continues, the exact loss figure could still shift in either direction.
How did a $1.12 million flash loan break the exchange rate?
A flash loan is a loan that gets taken out and repaid within a single transaction. If the money can't be repaid, the whole transaction simply reverses, as if it never happened. That makes the loan nearly risk-free for the lender, while turning into an almost free weapon for an attacker. That's exactly why flash loans have become a favorite tool for DeFi attacks in recent years.
The attacker borrowed $1.12 million in USDC from the lending protocol Kamino, then ran a series of rapid swaps into USDT to shift the exchange rate inside the Allbridge Core pool. In a stablecoin pool like this one, the more of one asset flows in, the cheaper it gets relative to the other. A large volume of fast trades let the attacker artificially tilt that ratio in their favor, and that imbalance is exactly what the whole scheme relies on.
Here's how the attack unfolded step by step:
- The move: the attacker took out a $1.12 million USDC flash loan with no collateral, repaying it within the same transaction
- a series of rapid USDC-to-USDT swaps artificially shifted the internal exchange rate of the Allbridge Core pool
- withdrew liquidity at the resulting, distorted rate in their favor
- repaid the Kamino loan and kept the difference, which made up most of the loss
In its post, the team added that some of the funds slipped away through a brief arbitrage window. It opened up because of the pool imbalance and, for a short time, let not just the attacker but a few other users who spotted the odd rate profit as well. Allbridge asked anyone who took advantage of it to return the surplus, since that money would go toward compensating liquidity providers. How many people will actually respond to that request remains to be seen.
Bridges have been the top hacker target since May
The Allbridge Core hack is at least the sixth attack on a cross-chain bridge since May 2026. Bridges hold large pools of funds that back tokens on the other side of the network. Drain that liquidity, and the whole system is left without backing. For attackers, that makes bridges one of the most attractive targets in DeFi, and the second quarter of 2026 already stood out for its record number of hacks across the sector.
Together, these four incidents cost the protocols roughly $8.6 million in under three years, and that's only counting the attacks that made it into public analytics.
Interestingly, this isn't the first time this has happened to Allbridge. Back in April 2023, the protocol lost $573,000 to a flash loan attack on its BNB Chain pool. In that case too, the attacker acted as both liquidity provider and trader, exploiting a flaw in a smart contract. The similarity between the two attacks suggests the team never fully fixed the underlying weakness that lets pools get manipulated on price, even though more than three years have passed since the first one.
What happens to affected users now?
Taiko, another protocol from the list above, restored its bridge 11 days after its hack, returning user funds through a four-step recovery plan. Allbridge hasn't given a timeline yet. The company has only said the investigation is ongoing and the team is still assessing the full scale of the loss.
Anyone who keeps assets specifically in bridges, rather than on an exchange or in a wallet, should keep one thing in mind. There's usually no insurance backstop there. Getting funds back depends on the project team's goodwill and the attacker's willingness to give back part of the loot, and that doesn't happen every time. Sometimes teams negotiate a partial return with the attacker in exchange for dropping legal action, but that's the exception rather than the rule.
What does this mean for cross-chain bridge users?
Flash loan attacks are hard to rule out entirely, since they don't exploit a coding bug but the basic mechanics of liquidity pools. Changing how a pool prices assets isn't simple. It means trading off either transaction speed or convenience for regular users, and DeFi developers are rarely willing to make that trade for security that most users only notice after a hack.
So anyone using bridges should keep a closer eye on how much they leave sitting there, and avoid parking liquidity for longer than necessary. It makes sense to keep only the amount needed for a specific transfer in a bridge and store the rest on an exchange or in a cold wallet. Solana, where this incident took place, remains one of the busiest networks for cross-chain activity. Similar stories will likely keep happening until protocols rethink how they protect their pools.




Comments
Your email address will not be published. Required fields are marked *