Allbridge, the team behind the popular cross-chain stablecoin bridge Allbridge Core, has officially hit the pause button on its protocol following a major security breach. Over the weekend, attackers managed to drain $1.65 million from the platform. The exploit specifically targeted Allbridge Core’s Solana deployment, with the culprits quickly moving the stolen assets over to Ethereum and hiding them within privacy pools before the team could fully intervene.
In a public statement released on Sunday, the company confirmed the security incident and announced the temporary suspension of the protocol while they conduct a thorough investigation. They also urged any users with liquidity remaining in the affected pools to withdraw their funds immediately as a protective measure.
How the $1.65 Million Flash Loan Attack Happened
According to blockchain analytics from Onchain Lens, the attacker executed a highly coordinated financial maneuver known as a flash loan attack. The process began with the attacker borrowing $1.12 million in USDC from Kamino. Immediately after securing the loan, they performed a rapid series of swaps between USDC and USDT. This aggressive trading activity successfully distorted the stablecoin exchange rate within Allbridge Core’s liquidity pools.
With the pool’s rates artificially manipulated, the attacker withdrew liquidity at the newly distorted prices. This allowed them to easily repay the initial $1.12 million flash loan while pocketing the significant difference as pure profit. The manipulation was so severe that it created a temporary window for positive arbitrage on the platform.
In the aftermath, the Allbridge team noted that some regular users may have inadvertently profited from this temporary imbalance. They have publicly requested that anyone who took advantage of the arbitrage window consider returning the funds, promising that all recovered money will go directly toward making the affected liquidity providers whole again.
A Growing Trend in Cross-Chain Bridge Vulnerabilities
Unfortunately, this is not the first time Allbridge Core has fallen victim to this exact type of exploit. Back in April 2023, the platform suffered a similar flash loan attack on its BNB Chain pool. In that instance, an attacker acting as both a swapper and a liquidity provider exploited a smart contract flaw to manipulate prices, walking away with roughly $573,000 in BUSD and USDT.
Zooming out, the broader cryptocurrency ecosystem is facing a severe string of similar attacks. The recent Allbridge breach marks at least the sixth time a cross-chain bridge has been successfully targeted since May alone. Because bridges must hold massive pools of locked funds to back the assets moving between different blockchains, they represent highly lucrative targets for sophisticated hackers.
This trend has been painfully visible across the industry in recent months. In June, the Ethereum layer-2 network Taiko was forced to urge users to withdraw assets and completely halt its bridge operations for 11 days after an exploit drained $1.7 million. Just weeks before the Taiko incident, Secret Network suffered a devastating $4.67 million loss when an “infinite mint” bug in a vulnerable smart contract allowed attackers to create unbacked versions of wrapped assets.