Allbridge Core halts after Solana flash-loan attack on stablecoin pools
Security & Exploits ·
Allbridge paused its Core cross-chain protocol after an attacker manipulated USDC/USDT pool pricing on Solana, with reported losses ranging from $1.1M to $1.65M depending on the source.
Allbridge confirmed the incident and the pause in a post on X, directing users to updates on the exploit's scope and next steps (x.com). Separate reporting put the stolen amount at $1.65M, tied to a flash loan attack that exploited Solana-based stablecoin liquidity pools (decrypt.co). The Block also covered the exploit, detailing how the attacker's actions distorted pool pricing before extracting funds (theblock.co).
The mechanism follows a familiar flash-loan pattern: an attacker borrows a large, uncollateralized sum for a single transaction, uses it to skew the relative pricing inside a liquidity pool, and then trades against that distorted price before repaying the loan in the same transaction. In this case the target was Allbridge Core's USDC/USDT pool on Solana, where the manipulated exchange rate allowed the attacker to withdraw more value than they deposited. A wallet address tied to the exploit has been surfaced on Nansen's profiler tool, allowing on-chain observers to track subsequent fund movement (app.nansen.ai).
Multiple accounts of the incident describe the stolen funds being bridged from Solana to Ethereum after the attack, and Allbridge has paused the protocol while urging liquidity providers to withdraw their positions. Eight distinct sources are tracking the cluster of reports around this exploit, with figures converging more consistently around the $1.65M mark in later coverage than the initial $1.1M estimate. Broader context on how flash-loan and oracle-manipulation exploits function across DeFi and bridge protocols is outlined in a general explainer on exploit mechanics (leviathan.news).
What remains unresolved is the exact final tally of losses, whether the discrepancy between the $1.1M and $1.65M figures reflects different accounting windows or asset valuations, and whether any portion of the bridged funds on Ethereum can be traced, frozen, or recovered. Allbridge has not indicated a timeline for resuming Core operations, and it is not yet known whether the pool design flaw exploited here affects other chains where Allbridge operates similar liquidity pools.