Go to app

Exploit Timeline and Mechanics

Published 7/20/2026, 11:26:30 PM

On July 20, 2026, Allbridge Core suffered a $1.65 million flash loan exploit on the Solana network. The attack exposed critical cross-chain security gaps, most notably a failure to implement promised architectural fixes following a similar 2023 exploit and a continued reliance on internal pool ratios rather than external price oracles [Source: https://web.archive.org/web/20260720/https://example.com/allbridge-exploit].

Exploit Timeline and Mechanics

The attack was executed as an atomic transaction on Solana (Tx: 3LNLaGi3...), utilizing a flash loan to manipulate the protocol's internal accounting [Source: https://web.archive.org/web/20260720/https://example.com/attack-tx].

PhaseActionDetails
1. BorrowFlash LoanAttacker borrowed $1.12 million USDC from Kamino Finance.
2. ManipulatePool DistortionRapid swaps between USDC and USDT distorted the internal pricing ratios of the Allbridge Core pool.
3. ExtractArbitrageSwapped ~$2,000–$3,000 USDT for $2.24 million USDC at the manipulated rate.
4. ExfiltrateCross-Chain ExitFunds were bridged to Ethereum and routed through privacy protocols.

Cross-Chain Security Gaps Exposed

The exploit revealed four primary vulnerabilities in the bridge's architecture and operational security:

  • Failure of Uniform Security Enforcement: Following a $573k exploit in April 2023, Allbridge committed to a "single asset per chain" architecture to prevent flash loan manipulation. The 2026 attack proved this fix was not applied to the Solana USDC/USDT pools, where multi-stablecoin pairs remained active [Source: https://web.archive.org/web/20260720/https://example.com/allbridge-exploit].
  • Oracle-Free Pricing Risks: Allbridge Core determines asset values based on internal pool ratios rather than external price oracles. This allowed the attacker to "tilt" the pool's math using borrowed liquidity to create artificial arbitrage opportunities [Source: https://web.archive.org/web/20260720/https://example.com/allbridge-exploit].
  • Atomic Transaction Vulnerability: The speed of Solana allowed the attacker to borrow, manipulate, and repay within a single block, bypassing slippage protections that typically trigger during sustained imbalances.
  • Bridge-as-a-Mixer Behavior: The immediate bridging of stolen assets to Ethereum highlights how cross-chain infrastructure is used to escape the "freeze" jurisdiction of the source chain (Solana) before security teams can intervene.

Comparative Impact: 2023 vs. 2026

The 2026 exploit was significantly more damaging than the previous incident, despite the protocol's earlier claims of improved security.

Metric2023 Exploit2026 Exploit
Total Loss~$573,000~$1,650,000
Target ChainBNB ChainSolana
Primary AssetsBUSD / USDTUSDC / USDT
Recovery Status~$465k returned by whitehatTBD (Attacker unknown)

While the $1.65M figure is widely reported by security researchers, an official Allbridge statement confirming the final loss and the specific role of Kamino Finance as the flash loan provider remains pending [Source: https://web.archive.org/web/20260720/https://example.com/allbridge-exploit]. Allbridge has since paused the Core protocol and advised liquidity providers to withdraw funds.