Allbridge pauses cross-chain bridge after $1.65M exploit
Allbridge pauses crosschain bridge operations after a reported $1.65 million exploit on Allbridge Core’s Solana deployment. The protocol was paused as a precaution while investigators review a flash-loan attack that allegedly manipulated stablecoin exchange rates before stolen funds moved to Ethereum.
Key Takeaways
- Allbridge Core paused its cross-chain bridge after a Sunday security incident that reportedly drained about $1.65 million.
- The exploit hit the Solana deployment; stolen funds were bridged to Ethereum and moved into privacy pools.
- Onchain Lens reported a $1.12 million USDC flash loan from Kamino and rapid USDC/USDT swaps that distorted pool rates.
- Allbridge urged liquidity providers in affected pools to withdraw and asked arbitrageurs to return funds for LP compensation.
- The case is at least the sixth cross-chain bridge attack since May; Allbridge also faced a flash-loan exploit in April 2023.
What happened in the Allbridge Core exploit?
According to Cointelegraph, Allbridge said Allbridge Core was experiencing a security incident and paused the protocol while it investigates. In a Sunday post on X, the team told users with liquidity in affected pools to withdraw now.
The incident affected Allbridge Core’s Solana deployment. Reporting said the attacker had already bridged the stolen funds from Solana to Ethereum before moving them into privacy pools.
How did the attacker allegedly drain the funds?
The attacker allegedly used a flash loan and rapid swaps to manipulate the bridge’s stablecoin exchange rate. Onchain Lens reported the attacker made a $1.12 million USDC flash loan from Kamino, then carried out rapid USDC/USDT swaps that distorted the Allbridge Core stablecoin pool’s exchange rate.
Liquidity was then withdrawn at the manipulated rates. The $1.12 million USDC loan was repaid, and the attacker kept the difference. Allbridge said the pool imbalance created a temporary positive arbitrage window and asked anyone who took advantage to consider returning funds so they can go directly toward compensating affected liquidity providers.
Why does Allbridge pausing the bridge matter?
Bridges are attractive targets because they often hold large pools of funds that back bridged assets on destination blockchains. Cointelegraph reported the Allbridge Core exploit is at least the sixth attack targeting a cross-chain bridge since May.
Readers following Fintech & Crypto Alerts should treat an official pause as a cue to check exposure, follow withdrawal guidance for affected pools, and wait for investigative updates before restoring liquidity.
Has Allbridge been hit by a flash loan attack before?
Yes. In April 2023, Allbridge was exploited for $573,000 through a flash loan attack on its pool on BNB Chain. The attacker acted as both liquidity provider and swapper and exploited a smart-contract flaw that allowed swap-price manipulation, draining about $289,900 in BUSD and $290,900 in USDT.
Other recent bridge incidents cited in the same report include Taiko’s $1.7 million exploit, Secret Network’s $4.67 million “infinite mint” bug involving Axelar-wrapped assets, plus Gravity Bridge, Verus Bridge, and Butter Network. Allbridge has posted a warning on the Allbridge Core website while the current investigation continues.