On July 20, 2026, Allbridge, the company behind the cross-chain stablecoin bridge Allbridge Core, paused its protocol after an attacker drained roughly $1.65 million from its Solana deployment using a flash-loan pool-manipulation technique the project had already been burned by once before.
What happened
Allbridge Core lets users swap and bridge stablecoins by depositing into liquidity pools that hold pairs such as USDC and USDT, and it prices liquidity withdrawals off the ratio between the two assets in a pool. The attacker took out a roughly $1.12 million USDC flash loan from the Solana lending protocol Kamino, then executed a series of rapid USDC/USDT swaps through Allbridge's pools that deliberately skewed the ratio between the two stablecoins. Because withdrawals were valued against that distorted ratio, the imbalance let the attacker pull liquidity out at manipulated rates, repay the $1.12 million loan, and walk away with the difference — about $1.65 million, with some trackers putting the figure closer to $2 million. Security firm PeckShield flagged the incident and noted that the stolen funds were bridged from Solana to Ethereum, swapped into ETH, and partly routed toward privacy pools to frustrate tracing.
Aftermath
Allbridge paused the protocol as a precaution while it investigated, and asked liquidity providers in the affected pools to withdraw their funds. As of reporting, the stolen assets had not been recovered. The attack was Allbridge's second flash-loan pool manipulation: in April 2023, an attacker exploited an Allbridge pool on BNB Chain using the same class of technique, resulting in losses of roughly $570,000. A protocol that was drained via flash-loan pool manipulation in 2023 was drained via flash-loan pool manipulation again in 2026.
Why it matters
Allbridge Core is a stark reminder that pricing withdrawals off a live, manipulable pool ratio is dangerous when an attacker can rent millions in capital for a single block. The same stablecoin-AMM manipulation pattern felled Platypus Finance, and the technique rhymes with the flash-loan vault manipulation that drained Summer.fi earlier the same month. That Allbridge shipped a fix in 2023 and still fell to the same primitive three years later underscores how easily cross-chain liquidity venues re-introduce pool-manipulation risk. For a bridge — an asset class already scarred by incidents like Ronin — every pool whose price can be moved with borrowed money is a standing invitation.
Sources & on-chain evidence
- [01]cointelegraph.comhttps://cointelegraph.com/news/allbridge-core-pauses-cross-chain-bridge-after-165m-exploit
- [02]cryptotimes.iohttps://www.cryptotimes.io/2026/07/20/allbridge-core-hit-by-1-65m-solana-flash-loan-exploit-its-second-since-2023/
- [03]beincrypto.comhttps://beincrypto.com/allbridge-core-solana-exploit-paused/
- [04]cryptobriefing.comhttps://cryptobriefing.com/allbridge-exploit-solana-ethereum-bridge/
- [05]lcx.comhttps://lcx.com/en/cryptonews/allbridge-pauses-cross-chain-bridge-after-165m-exploit
- [06]x.comhttps://x.com/PeckShieldAlert/status/2079011150713561173