Allbridge suspended its Core cross-chain bridge protocol on July 20, 2026, following an exploit that drained approximately $1.65 million from its Solana deployment. The attacker leveraged a $1.12 million USDC flash loan to manipulate exchange rates and withdraw liquidity at a distorted price.
Details of the Exploit
The attacker initiated a flash loan from the lending platform Kamino and executed rapid USDC/USDT swaps to distort the exchange rate within the stablecoin pool on Allbridge Core. By creating an artificial price imbalance, the attacker was able to extract liquidity at inflated values, repay the original loan, and retain the remaining funds.
Allbridge publicly acknowledged the incident via X, urging liquidity providers in affected pools to withdraw their assets immediately. The company also encouraged anyone who benefited from the temporary arbitrage opportunity to consider returning the funds to help compensate impacted liquidity providers.
This attack marks another flash loan-related incident for Allbridge. In April 2023, a smart contract vulnerability in its BNB Chain pool led to a $573,000 loss. Some of those funds were reportedly recovered through cooperation with white-hat hackers, although this recovery has not been fully verified.
Earlier this year, in January 2026, Allbridge expanded its cross-chain stablecoin support by integrating with Algorand, shortly before this latest security breach.
The incident fits a wider pattern of cross-chain bridge exploits in 2026. Platforms such as Taiko's Ethereum layer-2 bridge lost $1.7 million in June but managed to reopen following a recovery plan. Secret Network suffered a $4.67 million loss due to an infinite mint bug, and several other bridges including Gravity Bridge, Verus Bridge, Butter Network, and Kelp DAO's LayerZero-powered bridge have been targeted recently. The latter experienced a massive $292 million exploit in April 2026.
This material is informational and not financial advice.



