Allbridge Flash Loan Attack Drains $1.65M — For the Second Time
0
0

A cross-chain bridge getting drained is almost routine at this point in DeFi — but the mechanics behind the latest Allbridge flash loan attack are worth understanding, because they reveal exactly how sophisticated these exploits have become. On July 20, Allbridge paused its Core protocol after an attacker extracted roughly $1.65 million from its Solana stablecoin liquidity pools, using a technique that turned the protocol’s own pricing logic against itself.
Key takeaways
- Allbridge paused its Core cross-chain protocol after a $1.65 million flash loan exploit on its Solana stablecoin pools.
- The attacker borrowed $1.12 million from Kamino to manipulate pool pricing, then swapped a few thousand dollars of USDT for roughly $2.24 million in USDC.
- Stolen funds were bridged from Solana to Ethereum and dispersed across multiple addresses.
- Allbridge is seeking to compensate affected liquidity providers and has asked arbitrage traders who profited from the price distortion to return those gains.
- A similar flash loan attack hit Allbridge’s BNB Chain pools in April 2023, draining around $573,000.
Allbridge halts protocol after $1.65 million flash loan exploit
Allbridge’s Core product moves native stablecoins — primarily USDC and USDT — across blockchains without issuing wrapped versions. That architecture depends entirely on the integrity of its liquidity pools. Once those pools are mispriced, the whole mechanism can be weaponized.
Attack mechanics and immediate impact
The attacker opened the sequence by taking out a $1.12 million flash loan from Kamino, a Solana-based lending protocol. Flash loans are borrowed and repaid within a single transaction block, making them essentially costless to attempt and extremely fast to execute. With that capital, the attacker rapidly swapped USDC and USDT back and forth, skewing the pools’ internal pricing ratios.
Once the pools were mispriced, the attacker moved in for the actual extraction: swapping what amounted to a few thousand dollars of USDT for approximately $2.24 million in USDC. That gap between input and output is the exploit in a nutshell — the pool’s distorted accounting made a catastrophically favorable rate appear legitimate.
The proceeds didn’t sit on Solana for long. According to blockchain security firms CertiK and PeckShield, as well as on-chain data flagged by Arkham Intelligence, the stolen assets were bridged from Solana to Ethereum almost immediately and then dispersed across multiple addresses, complicating any recovery effort.
Pause and user advisory
Allbridge halted the Core protocol while investigating and told liquidity providers to withdraw from the affected pools. The speed of the pause mattered — but it couldn’t undo the damage already done before the team had a chance to act.
How the pool distortion created an unintended opportunity
The price manipulation had a secondary effect that Allbridge openly acknowledged. With the pools severely imbalanced after the attacker’s exit, other traders spotted the mispricing and moved to capitalize on it — a window the team described as a “temporary positive arbitrage opportunity.” Those traders weren’t the attackers, but they walked away with funds that would otherwise belong to liquidity providers.
Allbridge publicly asked anyone who profited from that pricing distortion to return those funds to a designated address, stating the money would go directly toward compensating affected liquidity providers. The team also said it is preparing a detailed post-mortem report and remains committed to returning all affected funds. Whether that appeal translates into actual returns depends entirely on the goodwill of anonymous on-chain actors.
A pattern Allbridge knows too well
This is not Allbridge’s first encounter with this kind of attack. In April 2023, a nearly identical flash loan exploit targeted its BNB Chain pools, draining approximately $573,000. After that incident, Allbridge recovered most of the funds — reportedly around $465,000 — through a white-hat hacker arrangement and subsequently reworked how the protocol calculates liquidity and withdrawals. The fact that a conceptually similar attack succeeded again, on a different chain, raises a pointed question about whether those fixes went far enough.
The 2026 exploit is materially larger and spans two separate blockchain ecosystems, which complicates recovery considerably compared to the 2023 event. Tracing funds that have already been bridged and fragmented across Ethereum addresses is a different challenge than recovering assets that remained on a single chain.
Cross-chain bridges remain DeFi’s most exposed infrastructure
Rising toll from multi-chain exploits
Allbridge’s situation sits within a much broader and accelerating pattern. More than $840 million was lost to DeFi hacks in just the first five months of 2026, with cross-chain systems repeatedly accounting for some of the largest individual losses. The structural reason is straightforward: bridges hold concentrated liquidity, operate across heterogeneous security environments, and rely on complex pricing logic that attackers can probe for inconsistencies.
Just prior to the Allbridge incident, a bridge connecting Axelar and Secret Network was drained of $4.67 million after attackers exploited an “infinite mint” bug in a custom token contract — a completely different attack vector but the same category of target.
Why flash loan attacks keep working
Flash loans have been a known threat vector for years, yet they continue to find new victims. The reason isn’t that protocols are unaware of the risk — it’s that properly accounting for flash loan-induced price distortions in real time, without introducing other trade-offs, remains genuinely difficult. Every liquidity pool that prices assets internally is a potential surface for this kind of manipulation, and the cost of executing the attack approaches zero when the loan is repaid in the same transaction.
For Allbridge, the strategic and reputational stakes are now considerable. Having raised $2 million in 2022 to expand the bridge and fund security audits — and having overhauled its systems once after the 2023 attack — the team faces pressure to demonstrate that a second exploit doesn’t reflect a structural blind spot in how the protocol handles oracle-free pricing. The post-mortem report it has promised will be closely watched across the DeFi security community.
FAQ
What triggered the Allbridge flash loan attack?
An attacker used a $1.12 million flash loan from Kamino to manipulate the internal pricing ratios of stablecoin pools on Solana, which enabled them to drain approximately $1.65 million from Allbridge’s Core protocol.
How did the attacker move the stolen funds?
After extracting the funds, the attacker bridged the stolen assets from Solana to Ethereum and then dispersed them across multiple addresses, making recovery more difficult to trace.
Is Allbridge compensating affected liquidity providers?
Yes. Allbridge has stated its goal is to return all affected funds and is asking traders who profited from the temporary arbitrage window created by the price distortion to return those gains. The team is also preparing a detailed post-mortem report and a compensation plan for affected liquidity providers.
Has Allbridge experienced similar attacks before?
Yes. In April 2023, Allbridge suffered a similar flash loan attack that drained around $573,000 from its BNB Chain pools. The team recovered most of those funds and updated its liquidity and withdrawal calculations following that incident.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
0
0
Securely connect the portfolio you’re using to start.





