Allbridge halted its Core bridge on July 20 following a $1.65 million exploit targeting stablecoin liquidity pools on the Solana network, blockchain security firms PeckShield and CertiK reported. The attacker manipulated USDC and USDT pools by leveraging a $1.12 million flash loan, then transferred the illicit gains to Ethereum.
Exploit Mechanics and Impact
The attacker took a flash loan from the Solana lending protocol Kamino, repaid within a single transaction, to distort the internal ratios of Allbridge's stablecoin pools. Rapid swaps between USDC and USDT skewed pool balances, enabling the withdrawal of assets at advantageous rates, according to analysis by Onchain Lens.
Allbridge Core facilitates cross-chain movement of native stablecoins using liquidity pools rather than wrapped tokens. The manipulation caused imbalances, opening a temporary arbitrage window. Stolen funds were bridged to Ethereum addresses and dispersed into various wallets. The protocol urged traders who profited from the price distortion to return funds to make liquidity providers whole.
This incident recalls a similar flash loan attack earlier in 2023, which drained about $650,000 from Allbridge's BNB Chain pools. Afterward, Allbridge committed to using a single liquidity pool per chain to prevent same-transaction flash loan manipulations. However, the July attack exploited a multi-stablecoin pool configuration on Solana, a setup the prior fix was designed to avoid.
Allbridge has yet to disclose how much of the $1.65 million remains unrecovered or when it plans to resume Core bridge operations.



