TL;DR
- Allbridge paused its cross-chain protocol after a flash loan exploit drained approximately $1.65 million from its pools on Solana.
- The attacker took out a $1.12 million loan from Kamino to manipulate the internal pool ratios and withdraw assets at favorable rates.
- The stolen funds were transferred from Solana to Ethereum and dispersed through mixing protocols to hinder tracing.
Allbridge suspended its cross-chain protocol after an attacker drained approximately $1.65 million from its stablecoin liquidity pools on the Solana network, according to reports from blockchain security firms CertiK and PeckShield. The project team confirmed the incident and asked affected liquidity providers to withdraw their funds immediately.
The protocol operates as a bridge between blockchains that do not communicate natively. Its Core product uses liquidity pools to transfer stablecoins such as USDC and USDTÂ without issuing wrapped versions of the assets, making it critical infrastructure for users moving value across networks.
Allbridge Core is experiencing a security incident.
We have paused the protocol as a precaution while we investigate.If you have liquidity in affected pools, please withdraw now.
The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage… pic.twitter.com/Ovg7yT35SM
— Allbridge (@Allbridge_io) July 19, 2026
What Happened to Allbridge
According to analytics firm Onchain Labs, the attack began with a flash loan of $1.12 million in USDC obtained from Kamino, the Solana lending protocol. The attacker executed rapid swaps between USDC and USDT to distort the internal ratios of the protocol’s pools, which allowed them to withdraw liquidity at artificially favorable rates. The loan was repaid within the same transaction, a characteristic mechanism of flash loans that eliminates counterparty risk for the attacker.
🚨 Allbridge Core exploited for $1.1M+ on @solana.
Attack flow:
$1.12M USDC flash loan from @kamino
↓
Rapid USDC/USDT swaps distort #Allbridge stablecoin pool ratios
↓
Liquidity withdrawn at manipulated rates
↓
Flash loan repaid within the same transaction
↓
~$1.1M… pic.twitter.com/vvKNxuFVZg— Onchain Lens (@OnchainLens) July 20, 2026
Once the funds were extracted, they were transferred to an address on Ethereum and dispersed through mixing protocols to hinder tracing. The Allbridge team also acknowledged that the imbalance generated in the pools created a temporary arbitrage opportunity, and publicly asked those who took advantage of that price distortion to voluntarily return the funds in order to compensate the affected liquidity providers.
This is not the first time Allbridge has suffered this type of attack. In 2023, a similar exploit drained approximately $650,000 from its pools on BNB Chain. On that occasion, the company claimed to have recovered most of the funds and announced changes to its liquidity mechanisms and withdrawal calculations. Allbridge had raised $2 million in 2022 to expand the bridge and fund security audits, which makes the recurrence of this attack vector raise doubts about the effectiveness of the measures implemented.



