Allbridge Core has paused its cross-chain stablecoin bridge after a flash loan exploit drained roughly $1.65 million from its Solana deployment. The protocol halted operations while the team investigates the incident and assesses affected liquidity pools.
The exploit targeted Allbridge Core’s USDC and USDT liquidity structure on Solana. On-chain analysts said the attacker used a $1.12 million USDC flash loan from Kamino to distort pool ratios before withdrawing funds at favorable rates.
Allbridge Core is experiencing a security incident.
We have paused the protocol as a precaution while we investigate.If you have liquidity in affected pools, please withdraw now.
The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage… pic.twitter.com/Ovg7yT35SM
— Allbridge (@Allbridge_io) July 19, 2026
Stablecoin Pool Pricing Became the Attack Surface
Allbridge Core is built around native stablecoin transfers across EVM and non-EVM chains. Its own product page describes the protocol as a cross-chain stablecoin swap system using native liquidity pools rather than wrapped assets.
That design can improve stablecoin transfer simplicity, but it also makes pool accounting and internal pricing logic critical. In this case, the attacker used rapid USDC and USDT movements to create a temporary imbalance, then extracted value before the system could normalize.
#PeckShieldAlert @Allbridge_io Core was exploited for ~$1.65M.
The exploiter has bridged the stolen funds from #Solana to #Ethereum pic.twitter.com/ZOZysmJcAH
— PeckShieldAlert (@PeckShieldAlert) July 20, 2026
The stolen funds were later bridged from Solana to Ethereum and routed through privacy tools, complicating recovery and forensic tracking. Security firms PeckShield and CertiK also flagged the movement of funds away from Solana.
We have seen a security incident on Allbridge Core Solana.https://t.co/HvLDMqGxSF
~$1.65M assets were stolen and bridged to an Ethereum address
0x651591b68A9c9650FB23F642162353306281ffDe before further dispersion.Stay Vigilant!https://t.co/GwVbxS2Iy9 pic.twitter.com/6WCoVK4jZA
— CertiK Alert (@CertiKAlert) July 20, 2026
Protocol Response Focuses on Liquidity Protection
Allbridge paused Core as a precautionary containment measure and urged users with liquidity in affected pools to withdraw while the investigation continues. The team has also said a full incident report is being prepared.
The breach echoes Allbridge’s earlier 2023 flash loan exploit, when the protocol lost about $573,000 from BNB Chain pools after an attacker manipulated swap pricing while acting as both liquidity provider and swapper.
The incident highlights a recurring risk for bridge protocols that rely on pooled liquidity. Even when assets are stablecoins, temporary price distortions can create extraction opportunities if pool logic can be manipulated within a single transaction.
Allbridge Core remains paused while the team works through recovery and remediation. The next useful indicators will be the final loss confirmation, a technical postmortem, affected LP accounting, patch details and a clear timeline for whether Core resumes in its current form or transitions fully to a redesigned bridge model.
