Go to app

Incident Summary

Published 7/20/2026, 6:17:44 PM

On July 19–20, 2026, Allbridge Core’s Solana-based liquidity pools were exploited for approximately $1.65 million through a sophisticated flash loan attack. The attacker manipulated the protocol's internal pricing state within a single transaction to withdraw liquidity at distorted rates, bypassing existing security measures.

Incident Summary

The exploit targeted native stablecoin pools (USDC/USDT) on the Solana network. Security firms CertiK and PeckShield confirmed the total loss at approximately $1.65 million.

MetricValueSource
Total Loss~$1.65 million[Verified: CertiK/PeckShield]
Flash Loan Amount$1.12 million USDC[Source: https://www.coindesk.com]
Flash Loan SourceKamino (Solana Lending Protocol)[Source: https://www.kucoin.com]
Target NetworkSolana[Source: https://www.tradingview.com]
StatusProtocol Paused[Source: https://finance.yahoo.com]

Technical Mechanics of the Attack

The attack was executed in a single, atomic transaction on the Solana blockchain, following these steps:

  1. Flash Loan Acquisition: The attacker borrowed $1.12 million USDC from Kamino, a prominent Solana lending protocol [Source: https://www.lcx.com].
  2. Pool Manipulation: Using the borrowed funds, the attacker performed high-volume swaps between USDC and USDT within the Allbridge Core pools. These swaps were designed to drastically shift the ratio of assets in the pool.
  3. Value Extraction: By distorting the internal pool state, the attacker was able to withdraw liquidity at a "manipulated" favorable rate that did not reflect the true market value of the assets.
  4. Repayment and Exfiltration: The original $1.12 million loan was repaid to Kamino within the same transaction. The remaining profit (~$1.65 million) was bridged from Solana to Ethereum and routed through privacy protocols to obscure the trail.

Reported Solana Transaction ID: 3LNLaGi36bqoSBFBqcQ3ZvDbnGCxrxu4rqahZrnfHZjKSYxfR1mqiCXtBXjjeBmoRQDeSiKxZ7c1nFb8pBgTY39Q [Note: not independently confirmed].

Root Cause and Vulnerability

The exploit targeted a fundamental flaw in Allbridge Core's cross-chain bridge architecture:

  • Pricing Vulnerability: The protocol's pricing and internal state were calculated based on the immediate pool ratio. This ratio could be moved significantly by a single large transaction (a flash loan), creating a temporary price discrepancy [Note: not independently confirmed].
  • Lack of TWAP: The absence of a Time-Weighted Average Price (TWAP) mechanism or multi-block safeguards allowed the attacker to exploit this discrepancy before the protocol could adjust to the true market price [Note: not independently confirmed].
  • Bypassed Defenses: Following a similar exploit in April 2023 on the BNB Chain, Allbridge had implemented a Rebalancer Authority and automatic shutdown for extreme imbalances. However, because the entire manipulation occurred within one transaction, these safeguards were reportedly circumvented before they could trigger [Note: not independently confirmed].

Current Status

Allbridge Core has paused its operations to investigate the breach. The protocol has reportedly provided a return address for the attacker (0x01a494079DCB715f622340301463cE50cd69A4D0) in hopes of negotiating a recovery, similar to the partial recovery achieved after their 2023 incident [Note: return address and 2023 recovery details not independently confirmed].