Loading prices…
🩸BEARISH

Allbridge halts Solana pools after $1.65M flash loan exploit

The attacker used a $1.12M flash loan from Kamino to skew USDC/USDT pool ratios, withdrew at favorable rates, and bridged proceeds to Ethereum.

Allbridge halts Solana pools after $1.65M flash loan exploit
Allbridge halts Solana pools after $1.65M flash loan exploit
Allbridge halts Solana pools after $1.65M flash loan exploit
Allbridge halts Solana pools after $1.65M flash loan exploit

Allbridge Core has paused its cross-chain stablecoin bridge after an attacker drained roughly $1.65 million from its Solana liquidity pools on Tuesday, according to security firms CertiK and PeckShield. The attacker took a $1.12 million flash loan from Solana lending protocol Kamino to rapidly swap USDC and USDT, skewing the pools' internal ratios before withdrawing assets at favorable rates. Stolen funds were then bridged to an Ethereum address and dispersed across additional wallets, with the current residual balance still being traced.

Allbridge Core operates a bridge that moves native stablecoins such as USDC and USDT between chains without issuing wrapped versions, settling through liquidity pools. The protocol told liquidity providers to withdraw from affected pools while it investigates, and publicly asked traders who profited from the resulting pricing distortion to return funds for LP compensation.

Why it matters

This is Allbridge's second flash-loan incident. In 2023 a similar attack drained roughly $650,000 from its BNB Chain pools, with the firm later saying it recovered most of the funds and rewrote its liquidity and withdrawal calculations. The repeat pattern is the harder story to defend: the fixes from 2023 were sold as the remediation, and a near-identical vector on Solana suggests either incomplete rollout across deployments or a shared economic-design weakness that survives the patch.

Market impact

The exploit hits at a moment when bridge TVL has become a structural marker for cross-chain DeFi risk pricing, and Solana liquidity pools in particular have grown their share of stable routing volume over the past two quarters. The immediate fallout is contained: Allbridge is a mid-tier bridge, not a critical infrastructure dependency, and the $1.65M loss is small relative to the multi-million-dollar drains that have hit larger venues this year. Watch for two signals: how much of the bridged proceeds the attacker fails to launder, which sets the precedent for how aggressively the protocol can negotiate recovery, and whether any of the same Kamino flash-loan liquidity surfaces in the next exploit.

Related tokens
$SOL

Frequently asked questions

  1. How did the Allbridge exploit work?

    The attacker took a $1.12M flash loan from Kamino on Solana, rapidly swapped USDC and USDT to skew pool ratios, then withdrew assets at favorable rates before bridging proceeds to Ethereum, netting roughly $1.65M.

  2. Which Allbridge pools were affected?

    The exploit hit Allbridge Core's Solana liquidity pools used to settle native USDC and USDT between chains. Allbridge paused the protocol and told LPs to withdraw from affected pools.

  3. Has Allbridge been exploited before?

    Yes. In 2023 a similar flash-loan attack drained roughly $650,000 from Allbridge's BNB Chain pools. The firm later said it recovered most of those funds and rewrote its liquidity and withdrawal calculations.

  4. Is the $1.65M Allbridge loss user-fund or treasury loss?

    The loss came out of Allbridge's Solana liquidity pools, meaning liquidity providers bear the impact. Allbridge asked traders who profited from the pricing distortion to return funds for LP compensation.

  5. Where are the stolen funds now?

    Stolen assets were bridged to an Ethereum address and dispersed across additional wallets. The current residual balance under attacker control is still being traced by on-chain investigators.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 22h ago
Open original →