Allbridge Core was exploited for roughly $1.65 million on Monday, with the attacker bridging the stolen funds from Solana to Ethereum in a single cross-chain sweep. The protocol said it has paused the bridge as a precaution and is urging affected liquidity providers to withdraw immediately.
Why it matters
Allbridge sits in the cross-chain bridge category that has historically been the single most-targeted surface in DeFi. A successful drain routed through a legitimate bridge hop to a major L1 is the worst-case pattern: the funds are now in Ethereum liquidity, harder to freeze than assets stranded on the source chain. The protocol's pause suggests the team caught the exploit in-flight rather than after the fact, but the cross-chain routing means time-to-recovery is measured in block confirmations, not hours.
Market impact
The $1.65M figure is small relative to mega-exploits but lands on top of a year in which bridge security has remained the structural weak point for institutional DeFi adoption. Affected LPs are now exposed to a multi-day withdrawal queue and a governance vote on any recovery plan. Watch the bridge's TVL trajectory over the next 24 hours; a sharp drop would confirm LPs are exiting rather than waiting for a patch.
Frequently asked questions
-
How much was stolen in the Allbridge Core exploit?
Roughly $1.65 million was drained from Allbridge Core, with the attacker bridging the stolen funds from Solana to Ethereum.
-
What has Allbridge done in response to the exploit?
Allbridge paused the protocol as a precaution and urged affected liquidity providers to withdraw immediately.
-
Why is bridging stolen funds from Solana to Ethereum significant?
Once funds land in Ethereum liquidity through a legitimate bridge hop, they become harder to freeze than assets stranded on the source chain, accelerating the time-to-recovery problem.
-
How does this compare to previous bridge exploits?
The dollar figure is small relative to mega-exploits, but bridges have historically been the single most-targeted surface in DeFi, making the category itself a recurring structural risk.
-
What should affected liquidity providers expect next?
Affected LPs face a multi-day withdrawal queue and a likely governance vote on any recovery plan, with TVL trajectory over the next 24 hours the key signal of whether they are exiting or holding for a patch.