Allbridge Core Drained of $1.65M as $1.12M Flash Loan Skews Stablecoin Pool
Allbridge Core paused its Solana bridge after a flash-loan attack drained $1.65M, the sixth cross-chain bridge exploit since May 2026.

Allbridge Core lost $1.65 million in a flash-loan attack on Sunday, July 19, 2026, forcing the cross-chain stablecoin bridge to halt its Solana deployment. The exploit began with a $1.12 million USDC flash loan borrowed from Solana lending protocol Kamino, which the attacker then used to distort exchange rates inside Allbridge’s stablecoin liquidity pool before withdrawing funds at the manipulated price.
How the attacker engineered the price gap
Onchain investigator Onchain Lens traced the mechanics: the borrowed $1.12 million in USDC was pushed through rapid USDC/USDT swaps that skewed the pool’s internal exchange rate. With prices out of sync, the attacker withdrew liquidity at the artificially favorable rate, repaid the flash loan in full, and pocketed the difference. Security firms PeckShield and CertiK separately confirmed the attacker moved the stolen funds from Solana to Ethereum and then routed them into privacy-focused mixing pools, complicating any recovery effort.
Allbridge confirmed the breach on X shortly after it was detected: “Allbridge Core is experiencing a security incident. We have paused the protocol as a precaution while we investigate. If you have liquidity in affected pools, please withdraw now.”
Onchain Lens also flagged that the manipulated pool briefly created a profitable arbitrage window for opportunistic traders, separate from the attacker’s own extraction, and appealed for restitution: “The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage of it, please consider returning funds… this will go directly toward compensating affected LPs.”
Not Allbridge’s first flash-loan wound
This marks the second time Allbridge Core has been hit by a flash-loan exploit. In April 2023, attackers drained $573,000 from an Allbridge pool on BNB Chain — $289,900 in BUSD and $290,900 in USDT — by manipulating swap prices while acting as both liquidity provider and swapper. The 2026 incident is roughly triple the size of that earlier breach, underscoring that the pool-manipulation vector remains unresolved for the protocol years later.
Part of a wider bridge-attack wave
The Allbridge Core breach is at least the sixth cross-chain bridge exploit reported since May 2026, according to Cointelegraph. Bridges remain prime targets because they concentrate large pools of locked collateral backing assets minted on destination chains — a single price distortion or contract flaw can unlock outsized payouts for attackers. BeInCrypto separately noted that DeFi exploits across the sector totaled $57.8 million in losses for July 2026 alone, placing the Allbridge incident within a month already marked by elevated protocol risk.
For liquidity providers, the episode is a reminder that pausing a protocol after the fact does not reverse losses already extracted through price manipulation — it only limits further damage. Allbridge has urged users with exposure to affected pools to withdraw immediately while its investigation continues, though no timeline for a full resumption of Allbridge Core has been given.
Sources
Related articles
BNB Grabs 30.6% Weighting, Tops Grayscale Smart Contract Fund Over ETH, SOL
Grayscale's Q2 rebalance made BNB the top holding at 30.6% in its Smart Contract Fund, while GDLC lifted BTC, SOL and XRP…
Circle’s Arc Lands BlackRock, Visa, Mastercard as Validators for Sept 16 Launch
Circle names 11 founding validators for its Arc blockchain ahead of a Sept 16 mainnet launch, as USDC supply sits at $73.3B.
Mastercard Tests Crypto Credential Pilot Days After $1.8B BVNK Deal Closes
Mastercard and Borderless pilot shared identity checks for cross-border stablecoin transfers, days after Mastercard's $1.8B BVNK acquisition closed.