Allbridge Core halts bridge after flash-loan attack on Solana stablecoin pool
Security & Exploits ·
The cross-chain protocol suspended operations following an exploit that manipulated USDC/USDT pricing, though reported losses vary across sources.
Allbridge Core stopped its cross-chain bridge after an attacker used a flash loan to distort exchange rates in a Solana-based USDC/USDT pool, according to a statement from the project. Early figures put the loss at $1.1M, though separate reporting from Cointelegraph and The Block cites a larger figure of $1.65M tied to the same incident, leaving the precise scale of the theft unsettled.
The mechanism follows a familiar pattern in decentralized finance: a large, uncollateralized loan taken and repaid within a single transaction is used to temporarily skew the pricing that a liquidity pool relies on for swaps. By pushing the USDC/USDT exchange rate away from its intended peg-like balance, the attacker was able to extract value from the pool before prices could correct. Allbridge Core’s decision to pause signals an attempt to stop further withdrawals or trades while the exposure is assessed.
This is not an isolated case within the broader landscape of protocol attacks. A general reference resource on exploits, hosted at leviathan.news, frames such incidents as part of a wider category in which attackers weaponize a known or hidden weakness in code, infrastructure, or economic design to redirect funds for financial gain. That framework distinguishes a passive vulnerability from an active exploit, the latter being the actual sequence of actions that converts a flaw into a realized loss — precisely what appears to have happened with the manipulated stablecoin pool.
Both Cointelegraph and The Block corroborate the core facts: Allbridge Core paused its bridge, the attack centered on flash-loan-driven manipulation of stablecoin exchange rates, and the reported loss stands near $1.65M in their accounts, in contrast to the smaller $1.1M figure noted elsewhere. Onchain analysts cited in that reporting support the flash-loan mechanism as the root cause.
What remains unclear is which loss figure is accurate, whether the discrepancy reflects different accounting of stolen funds versus total funds affected, and what steps Allbridge Core will take before resuming operations. Also unresolved is whether any funds can be recovered or whether the protocol will compensate affected liquidity providers. Further detail on the timeline for restarting the bridge, or any post-mortem analysis of the exploited code path, has not yet been provided.