Allbridge Core Pauses Operations Following $1.65 Million Solana Bridge Exploit
The protocol fell victim to a flash loan manipulation scheme, marking the sixth major cross-chain bridge attack since May.

The cross-chain stablecoin bridge Allbridge Core has suspended its operations following a sophisticated security exploit on its Solana deployment that resulted in the theft of approximately $1.65 million.
The incident, which occurred on Sunday, represents the latest in a persistent wave of cyberattacks targeting decentralized finance (DeFi) infrastructure, specifically cross-chain bridges that facilitate asset transfers between disparate blockchain networks.
According to on-chain data, the attacker executed a flash loan attack to manipulate the protocol’s liquidity pools. The exploiter initiated the attack by securing a $1.12 million USDC flash loan from Kamino Finance, a protocol operating on the Solana blockchain. Using these borrowed funds, the attacker performed a series of rapid swaps between USD Coin (USDC) and Tether (USDT). These high-volume transactions artificially distorted the exchange rates within the Allbridge Core stablecoin pool.
By manipulating the pool’s balance, the attacker was able to withdraw liquidity at highly favorable, distorted rates. After repaying the initial $1.12 million USDC flash loan, the perpetrator walked away with approximately $1.65 million in illicit profits. The stolen assets were subsequently transferred from the Solana network to the Ethereum blockchain before being funneled into privacy pools to obscure their transaction history.
Following the detection of the exploit, Allbridge Core immediately paused its smart contracts as a precautionary measure to prevent further losses. The project team issued an urgent advisory instructing liquidity providers to withdraw their assets from the affected pools immediately.

In a public statement, Allbridge Core acknowledged the temporary positive arbitrage window created by the pool imbalance and appealed to the attacker or any participating arbitrageurs to return the drained funds, promising that recovered capital would be used to compensate affected liquidity providers.
This incident is not the first time Allbridge has fallen victim to smart contract exploits. In April 2023, the protocol’s BNB Chain deployment was targeted in a similar flash loan attack. In that instance, the attacker manipulated swap prices by acting simultaneously as a liquidity provider and a swapper, ultimately draining $289,900 in Binance USD (BUSD) and $290,900 in USDT, totaling roughly $573,000.
Cross-chain bridges have increasingly become the primary vector for exploits in the crypto space. Because these protocols must hold substantial reserves of collateral on one blockchain to back synthetic or bridged assets on another, they represent highly lucrative targets for hackers. The Allbridge Core exploit marks at least the sixth major attack on a cross-chain bridge since May.
Other notable bridge security breaches in recent months highlight the systemic risks facing interoperability protocols. In June, Ethereum layer-2 network Taiko suffered a $1.7 million exploit, prompting a temporary suspension of its bridge before a multi-step recovery plan allowed operations to resume 11 days later. Shortly before the Taiko breach, Secret Network experienced a $4.67 million exploit stemming from an “infinite mint” vulnerability in a smart contract handling Axelar-wrapped assets. Other recent targets in the cross-chain sector include Gravity Bridge, Verus Bridge, and the Butter Network, underscoring the ongoing security challenges in the multi-chain ecosystem.









