What to Know

  • Allbridge Core paused its cross chain stablecoin protocol after an exploit removed roughly $1.65 million from its Solana liquidity pools.
  • The attacker used a $1.12 million flash loan from Kamino, a Solana lending protocol, to rapidly swap USDC and USDT.
  • The strategy manipulated internal pool ratios, allowing the attacker to withdraw assets at favorable rates before moving funds across chains.
  • The stolen assets were bridged to an Ethereum address and later dispersed across additional addresses.
  • It is not currently clear how much of the stolen value remains under the attacker’s control.
  • Allbridge paused operations for investigation and advised liquidity providers to withdraw from affected pools.
  • Allbridge asked traders who benefited from the temporary pricing distortion to return funds for liquidity provider compensation.
  • The protocol suffered a similar flash loan attack in 2023 that drained roughly $650,000 from its BNB Chain pools.
  • Allbridge raised $2 million in 2022 to expand the bridge and fund security audits.

Allbridge Core Halts After Solana Pool Exploit

Allbridge Core has paused its cross chain stablecoin protocol after an attacker stole roughly $1.65 million from liquidity pools on Solana, adding another high profile incident to the long running security challenges facing decentralized finance infrastructure. The pause affects the protocol’s Core product, which is designed to help users move native stablecoins across blockchains that do not directly communicate with one another.

The exploit centered on Solana based liquidity pools containing USDC and USDT. The attacker used a $1.12 million flash loan from Kamino to rapidly alter the relationship between assets inside the pools. By changing those internal ratios, the attacker was able to withdraw assets at more favorable rates than normal market conditions would allow. The funds were then bridged to an Ethereum address and spread across additional addresses, making the final recovery picture uncertain.

Allbridge responded by pausing the protocol while the incident is investigated. The team also advised liquidity providers to withdraw from affected pools. That guidance reflects the main risk after this type of event: pool imbalances can continue to create unusual pricing conditions until liquidity, accounting, and withdrawal logic are stabilized. Allbridge also asked traders who profited from the pricing distortion to return funds so that affected liquidity providers can be compensated.

How the Flash Loan Strategy Worked

A flash loan is a blockchain based loan that is borrowed and repaid within the same transaction. In ordinary finance, borrowing normally requires collateral, documentation, and time. In decentralized finance, flash loans can provide large amounts of temporary liquidity as long as the loan is repaid before the transaction ends. If the repayment fails, the full transaction is typically reversed. That design makes flash loans useful for arbitrage, liquidations, and refinancing, but it also gives attackers a powerful tool for manipulating protocols that rely on internal pricing formulas.

In this case, the attacker used the $1.12 million Kamino flash loan to swap between USDC and USDT at speed. Those swaps manipulated the internal ratios of the affected Allbridge pools. Once the pool balance had shifted, the attacker could withdraw assets at rates that worked in their favor. The mechanism did not require a long lasting market move. It relied on short lived distortion inside the protocol’s own liquidity environment.

Stablecoin pools are often seen as lower volatility venues because the assets involved are designed to track similar values. That perception can reduce attention on slippage and pricing edge cases, even though the mechanics behind the pool remain highly sensitive to balance changes, liquidity depth, and withdrawal calculations. When a large, instant loan is used to force the pool away from its expected state, even a stablecoin pool can become vulnerable if safeguards do not fully account for extreme transaction patterns.

Why Cross Chain Bridges Remain High Value Targets

Allbridge operates in one of the most targeted areas of crypto infrastructure. Cross chain bridges exist because many blockchains cannot communicate directly. Users who want to move assets between networks depend on bridging systems, liquidity pools, validators, smart contracts, or other mechanisms that coordinate the transfer. That role makes bridges important, but it also concentrates risk. A single weakness can affect users across multiple ecosystems.

Allbridge Core is built around transferring native stablecoins such as USDC and USDT without issuing wrapped versions of those assets. That structure is designed to give users a more direct experience when moving stablecoin value across chains. However, the use of liquidity pools means the protocol must maintain accurate internal accounting while handling deposits, withdrawals, swaps, and bridge transactions. If an attacker can disrupt pool ratios, the resulting imbalance can turn into a direct extraction opportunity.

The movement of stolen assets to an Ethereum address also highlights a common challenge in cross chain security incidents. Once funds leave the original network, response teams must track activity across separate ecosystems. Assets may be dispersed across additional addresses, making it difficult to determine how much remains controlled by the attacker at any given moment. That uncertainty can complicate both recovery efforts and communication with affected users.

Liquidity Providers Face the Immediate Impact

Liquidity providers are central to the operation of protocols like Allbridge Core. They deposit assets into pools that other users rely on for swaps and transfers. In return, they may earn fees or other incentives. But when a pool is exploited, liquidity providers can face losses because their deposited assets are the source of the liquidity being manipulated or drained.

Allbridge’s instruction for liquidity providers to withdraw from affected pools reflects a cautious approach after the exploit. Even when the initial attack is over, imbalanced pools can continue to create abnormal conditions. Arbitrage traders may be able to profit from mispriced assets until the pool returns to equilibrium or is otherwise adjusted. That is why Allbridge asked traders who benefited from the temporary pricing distortion to return funds for liquidity provider compensation.

Such requests are not unusual after decentralized finance incidents, though their success can vary. Some traders may view their actions as ordinary arbitrage within public markets, while affected protocols may frame the profits as the result of exploit driven distortion. The outcome often depends on community pressure, negotiations, forensic tracing, and whether addresses involved can be connected to identifiable entities.

Echoes of Allbridge’s Earlier Attack

The latest incident is not the first time Allbridge has faced a flash loan related exploit. In 2023, the protocol suffered a similar attack that drained roughly $650,000 from its BNB Chain pools. Allbridge later said it recovered most of those funds and changed its liquidity and withdrawal calculations. The recurrence of a broadly similar attack type is likely to draw attention from security researchers and market participants focused on bridge risk.

The earlier event matters because it shows that cross chain liquidity design is difficult to secure against adversarial capital. Attackers do not need to hold large amounts of their own money if they can borrow enough in a flash loan to push a protocol into an abnormal state. This means defense cannot rely only on the assumption that manipulation is expensive. Protocols must also ensure that pool math, price checks, withdrawal logic, and emergency controls remain resilient when very large transactions arrive instantly.

Allbridge had raised $2 million in 2022 to expand the bridge and fund security audits. Security audits are an important part of decentralized finance development, but they do not eliminate risk. Code changes, new deployments, evolving liquidity conditions, and fresh attacker techniques can all create new exposure over time. For bridge operators, the challenge is continuous rather than one time.

What the Incident Means for DeFi Risk

The Allbridge Core pause is another reminder that decentralized finance risk is not limited to token volatility. Smart contract logic, liquidity design, cross chain message flow, and pricing assumptions can all become points of failure. Even when the assets involved are stablecoins, users still face protocol risk. Stable value does not mean stable infrastructure.

For users, the incident underscores the need to understand where funds are placed and how a protocol functions. A stablecoin in a wallet is different from a stablecoin deposited into a liquidity pool. Once assets are supplied to a pool, they become part of a shared mechanism that may be exposed to trader behavior, smart contract risk, and attacks using borrowed liquidity. Those risks can be difficult to evaluate without technical knowledge, which is why transparency around incident response is critical.

For the broader crypto market, the exploit reinforces the importance of real time monitoring and emergency response. Fast detection can limit damage, but the speed of flash loan attacks means prevention is often more important than reaction. Protocols that depend on internal pricing need safeguards that can identify extreme ratio changes, unusual transaction sequences, or withdrawal patterns that deviate from normal market behavior.

FXCOINZ will continue to monitor developments around the Allbridge Core pause, including any updates on fund tracing, liquidity provider compensation, and the protocol’s path toward resuming operations. Until more information is available, the key unresolved question is how much of the stolen value remains recoverable and whether affected pools can be safely restored.

Frequently Asked Questions (FAQs)

What happened to Allbridge Core?

Allbridge Core paused its cross chain stablecoin protocol after an attacker stole roughly $1.65 million from Solana liquidity pools. The incident involved manipulation of USDC and USDT pool ratios using a flash loan.

How much was stolen in the exploit?

The stolen amount was roughly $1.65 million. The funds were taken from Allbridge Core liquidity pools on Solana and then bridged to an Ethereum address before being dispersed across additional addresses.

What role did Kamino play in the incident?

The attacker used a $1.12 million flash loan from Kamino, a Solana lending protocol. The loan was used to rapidly swap USDC and USDT, which manipulated the pools’ internal ratios and enabled favorable withdrawals.

What is a flash loan?

A flash loan is a loan that is taken and repaid within the same blockchain transaction. If the loan is not repaid in that transaction, the transaction typically fails, which allows large amounts of temporary liquidity to be used without traditional collateral.

Why did Allbridge pause the protocol?

Allbridge paused the protocol while investigating the exploit and assessing the affected pools. The pause is intended to help contain risk, evaluate pool conditions, and support the response process for liquidity providers.

What should liquidity providers know?

Allbridge advised liquidity providers to withdraw from affected pools. The initial manipulation left the pools imbalanced, creating a temporary arbitrage opportunity and potential additional risk for deposited liquidity.

Did traders profit from the imbalance?

The pool manipulation created a temporary pricing distortion, and Allbridge asked traders who profited from that imbalance to return funds. The stated goal is to support compensation for liquidity providers affected by the exploit.

Has Allbridge been attacked before?

Yes. Allbridge suffered a similar flash loan attack in 2023 that drained roughly $650,000 from its BNB Chain pools. The firm later said it recovered most of the funds and changed its liquidity and withdrawal calculations.

Is it clear how much money the attacker still controls?

No. The stolen assets were bridged to an Ethereum address and dispersed across additional addresses, and it is not currently clear how much remains under the attacker’s control.

Photo by DS stories on Pexels