Allbridge suspends agreement due to lightning loan attack
According to blockchain security companies and project parties, Allbridge has suspended its agreement because an attacker stole approximately $1.65 million from the liquidity pool on its Solana chain through lightning loan. Allbridge allows users to transfer assets between different blockchains that themselves cannot communicate natively. Its core products use pools of native stablecoins (such as USDC and USDT) rather than minted packaged tokens. On Sunday, the project team said it had "suspended the agreement as a precaution" during the investigation and called on liquidity providers to withdraw funds from affected pools.
In a subsequent tweet, Allbridge noted that its team was "preparing detailed decomposition instructions" and post-mortem analysis reports, adding that "there is currently no threat to user mobility" as the team is working to restart Core features but no longer relies on liquidity pools. Allbridge confirmed an earlier tweet from security company PeckShield that claimed the loss was approximately $1.65 million and noted that attackers had bridged funds from Solana to Ethereum.
CertiK, another security company, detailed the attack's modus operandi: The attacker first borrowed a $1.12 million flash loan through Kamino, a loan agreement on Solana, and then made a series of rapid stablecoin conversions to distort the internal accounting mechanism used to price assets in the Allbridge pool. After the asset pricing in the pool was skewed, the attacker exchanged thousands of dollars of USDT for approximately $2.24 million of USDC, then bridged the proceeds to an Ethereum address and dispersed it to other addresses. It is unclear how much of the money is still recoverable.
The manipulation caused Allbridge's liquidity pool to be unbalanced, allowing other traders to buy mispriced assets for a while-what the team called a "short arbitrage window." The DeFi platform calls on all users who profit from the window to send funds to designated addresses, saying the funds will be "directly used to compensate affected liquidity providers." The team also said its "goal is to return all affected funds."
This is not the first time Allbridge has encountered such an attack. In April 2023, a similar flash loan loophole stole approximately US$573,000 from its BNB Chain pool; the project party later said it had recovered most of the funds and redesigned the liquidity calculation and withdrawal mechanism. Allbridge raised $2 million in 2022 to expand bridging capabilities and fund security audits.
Bridging protocols and the mobility pools they rely on have long been one of the most attacked infrastructures in the DeFi space. In the first five months of 2026 alone, losses caused by DeFi hacking exceeded US$840 million, and cross-chain systems contributed the single largest loss many times. Just last month, a bridge agreement between Axelar and Secret Network was stolen $4.67 million when attackers exploited an "unlimited casting" vulnerability in custom token contracts.
Allbridge's agreement remains suspended. How much of the $1.65 million can be recovered will depend on tracking the bridging funds-and whether the carry traders called on actually returned the money.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BNB
ETH