EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Allbridge Cross-Chain Bridge suspended service after a $1.65 million attack

2026-07-20 12:31:19
Bookmark

Cross-chain bridge Allbridge Core suspends agreement due to security incident, losing US$1.65 million

Allbridge, the company behind the cross-chain stablecoin bridge Allbridge Core, said it has temporarily suspended the agreement after a security incident occurred on Sunday that resulted in the theft of approximately US$1.65 million. The incident mainly affected the deployment of Allbridge Core on Solana, and the attackers allegedly transferred the stolen funds to Ethereum and then into the privacy pool.

Allbridge posted on the X platform saying it suspended the agreement as a "precautionary measure" while conducting an investigation and urging users to withdraw liquidity from the affected pool. The incident is the latest in a series of cross-chain bridge attacks earlier this year, highlighting the continued targeting of bridge-controlled liquidity that, once manipulated, can become invaluable.

Key Points

Allbridge Core suspended operations after reporting a $1.65 million incident involving Solana deployment. According to surveillance reports shared on the X platform, the attackers allegedly bridged funds from Solana to Ethereum and then moved them to the privacy pool. The on-chain analysis report pointed out that the attacker used a USDC flash loan of $1.12 million to distort the pricing of the stablecoin pool. Allbridge previously suffered a blitz loan-related attack on BNB Chain in 2023, highlighting recurring risk patterns in bridging liquidity pools. The incident is one of many bridging attacks since May, once again demonstrating that cross-chain mobility remains a continuing target for criminals.

Agreement suspended after Solana to Ethereum theft

Allbridge Core's suspension was triggered by what the company called a "security incident." According to Allbridge's statement on the X platform, the agreement has been terminated as a precautionary measure and the team is investigating and assessing the scope of impact. The company specifically recommends that if users have liquidity in the affected pool, they should be extracted. Such guidance is common after a bridging attack event, because the attacker's impact can go beyond the original theft-especially if pool pricing is manipulated and residual liquidity is temporarily mispriced.

Publicly shared surveillance information shows a fast-occurring sequence. An alert issued by CertiKAlert indicated that funds had been bridged from Solana to Ethereum after the incident, and the attackers allegedly routed the funds to the privacy pool.

How attackers manipulated stablecoin liquidity

Onchain Lens reported on the detailed mechanism behind the incident: The attacker allegedly borrowed a USDC flash loan of US$1.12 million from Kamino and then performed a rapid USDC/USDT conversion, disrupting the exchange rate of the Allbridge Core stablecoin pool. These transactions allegedly create a window into which pool imbalances can be exploited. The attackers then extracted liquidity at a manipulated and distorted exchange rate, repaid the original flash loan, and retained the difference between the withdrawal amount and the amount needed to settle the loan.

Allbridge later mentioned the result in its newsletter. The company said "pool imbalance creates a temporary positive arbitrage window" and added that anyone benefiting from it should consider returning the money. The company also said the value of the return would be used to compensate affected liquidity providers. The practical lesson for investors and traders is that bridging attacks are not just about the amount ultimately stolen. Price distortions and temporary arbitrage dynamics can lead to secondary effects-for example, liquidity providers who remain exposed to risk after initial manipulation can suffer losses unless the agreement is suspended and withdrawal guidance is followed.

Lightning loan model related to recurring bridging vulnerabilities

This is not the first time Allbridge Core has faced lightning loan pressure. The company and its infrastructure have been attacked before: According to technical analysis released by SolidityScan, in April 2023, Allbridge attacked a pool via lightning credit on BNB Chain. The incident allegedly involved an attacker who acted as both a liquidity provider and a redemption officer and exploited a loophole in business logic in smart contracts. The mechanism allowed attackers to manipulate exchange prices, resulting in the alleged theft of $289,900 in BUSD and $290,900 in USDT.

Although each bridging deployment and asset routing may vary, tactical continuity-flash lending combined with liquidity pool price manipulation-suggests a broader category of vulnerabilities. In many cross-chain designs, bridges rely on liquidity pools to support the issuance and redemption of bridged assets. If the pool's accounting and redemption logic can be affected in a single transaction sequence, an attacker may be profitable without long-term capital exposure. The near-term uncertainty facing users is whether Allbridge Core has thoroughly investigated the specific smart contract paths involved on Solana and whether other pools or liquidity routes were affected in addition to the reported $1.65 million.

Cross-chain bridges have been targeted since May

This Allbridge Core incident occurred amid a series of reported wave of bridging attacks. Previous media reports detailed how multiple agreements urged users to withdraw money or suspend bridge services after being attacked, reflecting that when attackers discover liquidity weaknesses, damage can spread quickly. In June, media reported that Taiko, the Ethereum second-layer network, urged users to withdraw assets after attackers used one of its bridging protocols to steal $1.7 million. Taiko reopened the bridge 11 days later after completing a four-step recovery plan. A few weeks ago, media reported that the Secret Network was attacked due to an "infinite casting" vulnerability in a vulnerable smart contract. The incident allegedly resulted in the theft of $4.67 million in unsecured Axelar packaging assets.

Other bridging failures mentioned in recent reports include media reports that Gravity Bridge was suspended after a reported $54 million attack, Verus Bridge was allegedly attacked and lost millions of dollars, and Butter Network lost almost all of its value after a reported trillion-dollar token mining vulnerability. Taken together, the pattern is consistent: the bridging system concentrates liquidity, which often translates into high returns for attackers, who can manipulate pricing, casting/destruction mechanisms, or settlement logic across chains. When agreements respond with suspensions and user withdrawal instructions, they are effectively trying to limit further exposure while conducting remedial work.

For users, the next focus is clear: whether Allbridge Core confirmed the full scope of the affected pools, when (if so) the protocol was restarted, and what security measures were described afterwards-particularly regarding pool immutability and lightning loan resistance. Until these details are clarified, liquidity providers should assume that without operational suspension, temporary pricing distortions may not be fully resolved.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP