Cross-chain protocol Allbridge paused its Core bridge on July 20 after an attacker drained roughly $1.65 million from its Solana liquidity pools, according to blockchain security firms PeckShield and CertiK.
"Allbridge Core is experiencing a security incident, and the protocol has been paused as a precaution," the team said, warning liquidity providers: "If you have liquidity in affected pools, please withdraw now."
Allbridge Core moves native stablecoins such as $USDC and $USDT across chains using liquidity pools, rather than issuing wrapped tokens. The attacker took out a $1.12 million flash loan — a loan borrowed and repaid within a single transaction — from Solana lending protocol Kamino, then rapidly swapped $USDC and $USDT to distort the pools' internal ratios before withdrawing assets at favorable rates, on-chain analyst Onchain Lens reported.
The stolen funds were bridged to an Ethereum address and dispersed across additional wallets. Allbridge said the manipulation left its pools imbalanced, creating a temporary arbitrage window, and asked traders who profited from the distortion to return funds to compensate affected liquidity providers.
A Repeat of 2023
The incident echoes a flash loan attack in 2023 that drained roughly $650,000 from Allbridge's BNB Chain pools. In its postmortem at the time, Allbridge committed to deploying a single liquidity pool per chain, an architecture intended to make same-transaction flash loan manipulation structurally impossible.
The July exploit targeted a $USDC and $USDT pool operating side by side on Solana — the multi-stablecoin configuration the earlier fix was meant to eliminate. Allbridge said it recovered most of the funds after the 2023 incident.
The protocol has not published a final accounting of how much of the $1.65 million remains under the attacker's control or laid out a timeline for resuming operations.