Share
Subscribe to the AlphaWire Newsletter
Cross-chain bridge protocol Allbridge Core has paused its Solana deployment after a security incident that blockchain security companies estimated caused about $1.65 million in losses, adding to a string of recent attacks targeting cross-chain bridges.
The protocol suspended operations on Sunday while investigators examined the exploit and urged users with funds in affected liquidity pools to withdraw them. Security companies CertiK and PeckShield said the attacker moved the stolen assets from Solana to Ethereum before dispersing them through privacy-focused protocols.
Allbridge Core is experiencing a security incident.
We have paused the protocol as a precaution while we investigate.If you have liquidity in affected pools, please withdraw now.
The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage… pic.twitter.com/Ovg7yT35SM
— Allbridge (@Allbridge_io) July 19, 2026
Preliminary onchain analysis indicates the attacker manipulated Allbridge Core’s USDC (USDC) and Tether’s USDt (USDT) liquidity pool on Solana using a flash loan rather than compromising user wallets.
According to Onchain Lens, the attacker borrowed about $1.12 million in USDC through the Solana lending protocol Kamino before executing rapid USDC and USDT swaps that distorted the pool’s pricing.
The attacker then withdrew liquidity at manipulated exchange rates, repaid the flash loan within the same transaction, and kept the difference. Onchain Lens estimated that more than $1.1 million was extracted directly, while PeckShield and CertiK placed the broader impact at $1.65 million.
🚨 Allbridge Core exploited for $1.1M+ on @solana.
Attack flow:
$1.12M USDC flash loan from @kamino
↓
Rapid USDC/USDT swaps distort #Allbridge stablecoin pool ratios
↓
Liquidity withdrawn at manipulated rates
↓
Flash loan repaid within the same transaction
↓
~$1.1M… pic.twitter.com/vvKNxuFVZg— Onchain Lens (@OnchainLens) July 20, 2026
Allbridge said the exploit left some pools temporarily imbalanced, creating what it described as a positive arbitrage opportunity. The team asked traders who benefited from the pricing discrepancy to return funds to a designated recovery address, saying any recovered assets would be used to compensate affected liquidity providers.
The incident is the second major exploit involving Allbridge in recent years. In April 2023, the protocol lost about $573,000 after an attacker manipulated swap pricing in a BNB Chain liquidity pool. Allbridge later recovered around $465,000 after offering the attacker a white hat bounty.
The latest attack comes amid a series of bridge security incidents across the sector. Ethereum layer-2 network Taiko temporarily shut down one of its bridge protocols after a $1.7-million exploit in June before restoring operations 11 days later. Secret Network also disclosed a $4.67-million exploit in May tied to an “infinite mint” vulnerability affecting wrapped assets.
While investigators have outlined how the attacker manipulated the liquidity pool, Allbridge has not released a technical post-mortem identifying the underlying vulnerability or announced when the protocol will reopen. The team said the investigation remains ongoing as it works to recover funds and assess the full impact of the incident.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share