EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Allbridge Core is hit by another flash loan attack, resulting in a loss of $1.65 million on Solana'

2026-07-22 00:16:50
Bookmark

Allbridge Core, a cross-chain stablecoin bridge, was attacked on July 19 and lost US$1.65 million. The attacker manipulated the exchange rate of the bridge pool through a series of fast exchange operations, which is the second time the agreement has suffered losses due to a lightning loan attack. Allbridge Core, a protocol that connects multiple blockchains and supports stablecoin transfers, suspended services on the Solana network after several blockchain security companies issued warnings.

Attack method: Borrowing funds distort exchange rates

The attacker first borrowed US$1.12 million in USDC from the liquidity agreement Kamino on Solana, and then used the funds to conduct large-scale rapid conversions between USDC and USDT, artificially distorting the exchange rate in the Allbridge Core stablecoin pool. After the exchange rate was manipulated in a favorable direction, the attackers extracted liquidity at a distorted price and subsequently repaid $1.12 million in flash loans and retained the difference. Blockchain security companies PeckShield and CertiK confirmed that the stolen assets were subsequently transferred across the chain from Solana to Ethereum and through a privacy pool to conceal their origin.

Intra-Pool Imbalances and Arbitrage Window

Allbridge issued a document on the X platform confirming the incident, saying that the agreement had been suspended as a precautionary measure and urging users with funds deposited in the affected pool to withdraw them as soon as possible. The team also pointed out that the distorted pool ratio briefly provided arbitrage opportunities for other participants and asked these users to voluntarily return the proceeds. Allbridge said the returned funds will be used to compensate affected liquidity providers.

Cross-chain bridges continue to be targeted

In recent months, cross-chain bridges have continued to face pressure from attackers. Since May 2026, the Allbridge Core attack is at least the sixth exploit of a bridge protocol. Cross-chain bridges hold a large pool of assets to support tokens on the target chain, making them a high-value target. In June this year, a bridging protocol of Taiko, the Ethereum Layer-2 network, was attacked and lost US$1.7 million. Its bridging service was suspended and reopened after an 11-day, four-step recovery process. During the same period, Secret Network lost $4.67 million due to an "infinite casting" vulnerability in a vulnerable smart contract that generated an unsecured version of Axelar encapsulated assets. In addition, Gravity Bridge, Verus Bridge and Butter Network also reported exploits during the same period. Allbridge said its investigation was still ongoing at the time of publication.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP