Allbridge Core Pauses After $1.65M Flash Loan Exploit
Allbridge Core paused its cross-chain bridge after an attacker exploited a Solana-based stablecoin pool and removed about $1.65 million. The attacker used a flash loan to manipulate the exchange rate between USDC and USDT before moving the proceeds from Solana to Ethereum.
The team stopped protocol operations while investigating the incident and reviewing the affected contracts. The pause prevents normal transfers through Allbridge Core, which connects stablecoin liquidity across EVM networks and chains including Solana, Sui, Stellar and Tron.
Attacker Uses $1.12 Million Flash Loan
The attack began with a flash loan of about $1.12 million in USDC from Kamino, a Solana-based lending and liquidity protocol. Flash loans allow users to borrow assets without providing collateral, provided the full amount is repaid within the same blockchain transaction.
The attacker used the temporary liquidity to make rapid swaps between USDC and USDT in an Allbridge Core pool. Those transactions changed the balance between the two stablecoins and distorted the exchange rate used by the protocol.
After changing the pool ratio, the attacker withdrew assets at a more favorable rate. The flash loan was then repaid within the same transaction, leaving the remaining funds under the attacker’s control.
Loss Estimates Reach $1.65 Million
Early security estimates placed the direct loss near $1.1 million, while later tracking valued the total stolen assets at approximately $1.65 million. The difference may reflect changing token prices, additional transfers or different methods used to calculate the amount removed from the protocol.
Allbridge had not released a complete technical report when the incident was first reported. The final loss could change as the team reviews pool balances, transaction costs and funds moved across multiple networks.
The available evidence points to manipulation of the stablecoin pool rather than a failure of the cross-chain messaging system. Allbridge Core uses liquidity pools to support stablecoin transfers between blockchains, making the accuracy of its swap calculations important to the security of user funds.
Stolen Funds Move to Ethereum
The attacker moved the stolen assets from Solana to Ethereum after completing the exploit. The funds were then converted into Ether, while some transactions reportedly used privacy tools intended to make the asset trail harder to follow.
Moving funds across networks does not prevent blockchain investigators from tracking them, but it can make recovery more difficult. Security firms and exchanges can still monitor identified addresses and may freeze assets if they reach centralized platforms.
PeckShield and CertiK were among the security companies tracking the movement of the stolen funds. Allbridge had not announced whether it had contacted the attacker or offered a reward for returning the assets.
Allbridge Has Faced a Similar Attack
Allbridge Core suffered another flash loan exploit in April 2023. That incident manipulated BUSD and USDT pool prices on BNB Chain and caused losses of about $570,000.
The protocol later relaunched with changes intended to reduce the risk of similar attacks. The latest incident will increase scrutiny of those protections and whether additional limits, pricing controls or real-time monitoring could have stopped the Solana exploit.
The team has not provided a reopening date for Allbridge Core. Normal operations are expected to remain paused until investigators identify the affected contracts and confirm that the remaining liquidity can be used safely.