Allbridge Core Pauses Operations After $1.65M Flash Loan Exploit on Solana

Allbridge Core has temporarily paused its Solana deployment following a security incident that drained an estimated $1.65 million from the protocol’s stablecoin liquidity pools. The cross-chain bridge operator confirmed the event on its official communication channels and advised liquidity providers in affected pools to withdraw their funds immediately while an internal review is underway.
The incident unfolded through a single-transaction flash loan attack, according to initial on-chain monitoring. The attacker reportedly borrowed approximately $1.12 million in USDC through the Kamino lending protocol to manipulate the balance between USDC and USDT within Allbridge Core’s Solana pools. By artificially distorting the pool’s internal pricing ratio, the attacker was able to withdraw liquidity at skewed rates before repaying the borrowed capital within the same transaction block.
Following the execution, tracker data showed the extracted assets were bridged from Solana to Ethereum and subsequently routed through privacy-focused protocols. Secondary coverage placed the total loss between $1.1 million and $1.65 million, with the exact figure remaining dependent on final reconciliation. Reporting on the incident noted that the pricing manipulation targeted the native stablecoin routing logic rather than external oracle inputs.
In response to the development, Allbridge has kept the Core protocol in a paused state. The team published an Ethereum address, 0x01a494079DCB715f622340301463cE50cd69A4D0, requesting that any arbitrage actors or unrelated third parties who captured yields from the pool distortion voluntarily return the gains to help compensate affected liquidity providers. The available documentation does not detail the specific contract function that allowed the ratio manipulation.
This marks the second major flash loan incident involving Allbridge Core since the protocol launched. In April 2023, a comparable pricing manipulation on the project’s BNB Chain deployment allowed an attacker to drain roughly $570,000 in stablecoins. The development team has not yet released a full technical post-mortem or confirmed the timeline for restoring operations, and the protocol remains paused while damage assessment and security reviews continue.






