- Allbridge paused its Allbridge Core protocol after a security incident drained $1.65 million from its Solana deployment.
- The attacker used a flash loan to manipulate the stablecoin pool’s exchange rate, then withdrew liquidity at manipulated rates.
- This is at least the sixth cross-chain bridge exploit since May, underscoring persistent vulnerabilities in bridge protocols.
- Allbridge Core previously suffered a similar flash loan attack in April 2023, losing $573,000 on the BNB Chain.
On Sunday, Allbridge, the company behind the cross-chain stablecoin bridge Allbridge Core, said it paused the protocol after a security incident that saw $1.65 million drained from its Solana deployment. The attacker bridged the stolen funds from Solana to Ethereum before moving them into privacy pools.
In a post on X, Allbridge stated, “We have paused the protocol as a precaution while we investigate. If you have liquidity in affected pools, please withdraw now.” According to Onchain Lens, the attacker made a $1.12 million USDC flash loan from Kamino, then executed rapid USDC/USDT swaps that distorted the stablecoin pool’s exchange rate.
The attacker withdrew liquidity at the manipulated rates, repaid the loan, and kept the difference. Allbridge added, “If you took advantage of it, please consider returning funds… this will go directly toward compensating affected LPs.” This exploit marks at least the sixth attack targeting a cross-chain bridge since May, following incidents at Taiko, Secret Network, Gravity Bridge, Verus Bridge, and Butter Network.
Notably, Allbridge previously suffered a flash loan attack in April 2023, losing $573,000 on the BNB Chain through a similar manipulation of swap prices. Lookonchain reported the attacker moved the funds across chains, highlighting the ongoing threat to bridge liquidity pools.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
