Summary

  • Allbridge, a cross-chain bridge, has halted its Core protocol after a hacker stole approximately $1.65 million from its Solana stablecoin liquidity pools.
  • The thief utilized a $1.12 million flash loan from the Kamino lending protocol to manipulate the pools’ internal pricing, allowing for cheap asset extraction which was then bridged to Ethereum.
  • Allbridge has urged liquidity providers to withdraw their funds and requested that traders who gained from the imbalance return their profits.

The cross-chain bridge Allbridge has temporarily suspended its protocol after an attacker successfully drained around $1.65 million from its Solana liquidity pools in a flash loan attack, as confirmed by both blockchain security firms and the project itself.

Allbridge facilitates the transfer of assets between blockchains that lack direct communication capabilities, using liquidity pools of stablecoins like USDC and USDT instead of minting wrapped tokens. On Sunday, the team announced it had "paused the protocol as a precaution" while investigating the incident, advising liquidity providers to withdraw their assets from the affected pools.

Allbridge Core is facing a security incident.
We have paused the protocol as a precaution while we investigate.

If you have liquidity in affected pools, please withdraw now.

The ensuing pool imbalance has created a temporary positive arbitrage opportunity. If you took advantage… pic.twitter.com/Ovg7yT35SM

— Allbridge (@Allbridge_io) July 19, 2026

In a subsequent tweet, Allbridge indicated that its team was "preparing a detailed breakdown" and a post-mortem report, reassuring users that "There is no threat to users' liquidity at this moment" as they work towards re-launching Core without liquidity pools.

Incident Details

Allbridge corroborated an earlier tweet from the security firm PeckShield, which estimated the loss at around $1.65 million, mentioning that the hacker bridged the assets from Solana to Ethereum.

Another security firm, CertiK, elaborated on the method used, revealing that the attacker borrowed $1.12 million via a flash loan from the Kamino lending protocol on Solana, executing a rapid series of stablecoin swaps to distort the internal pricing within Allbridge's pools.

#CertiKInsight 🚨

A security incident has occurred on Allbridge Core Solana. https://t.co/HvLDMqGxSF

~$1.65M in assets were stolen and bridged to an Ethereum address
0x651591b68A9c9650FB23F642162353306281ffDe before further distribution.

Stay Vigilant!https://t.co/GwVbxS2Iy9 pic.twitter.com/6WCoVK4jZA

— CertiK Alert (@CertiKAlert) July 20, 2026

Due to the mispricing of the pools, the attacker managed to exchange a few thousand dollars in USDT for around $2.24 million in USDC, which was subsequently bridged to an Ethereum address and dispersed to various others. The extent of the remaining funds is currently unknown.

This manipulation created an imbalance in Allbridge's pools, allowing other traders to exploit the mispriced assets—a situation described by the team as a "temporary positive arbitrage window." The DeFi platform has asked anyone who benefited from this opportunity to return the funds to a specified address, emphasizing that the money would be used to "compensate affected liquidity providers." The team reiterated, "Our goal is to return all affected funds."

Previous Incidents

This incident marks the second time Allbridge has faced such a challenge. In April 2023, a similar flash loan exploit resulted in a loss of about $573,000 from its BNB Chain pools; the project later reported that it had recovered most of the stolen funds and adjusted its liquidity and withdrawal calculations. In 2022, Allbridge secured $2 million in funding to enhance its bridge and support security audits.

Bridges and their associated liquidity pools have consistently been prime targets within the DeFi space. In the first five months of 2026 alone, over $840 million was lost to DeFi-related hacks, with cross-chain systems frequently accounting for some of the largest losses. Recently, a bridge between Axelar and Secret Network was compromised, resulting in a theft of $4.67 million due to an "infinite mint" bug in a custom token contract.

As Allbridge's protocol remains on hold, the recovery of the $1.65 million will depend on tracking the bridged assets and the willingness of the arbitrage traders to return the funds they profited from.

Daily Briefing Newsletter

Stay updated with the latest news stories each day, along with unique features, podcasts, videos, and more.