Another incident for the cross-chain bridge! Allbridge Core suffers a flash loan attack, losing $1.65 million

Cross-chain stablecoin bridge Allbridge Core’s Solana deployment was hit by a flash loan attack. After the attacker borrowed $1.12 million in USDC, they rapidly swapped to distort the bridge protocol’s stablecoin_pool_ exchange-rate mechanism, then arbitraged $1.65 million. The stolen funds were bridged to Ethereum and flowed into a privacy pool. This is the 6th cross-chain bridge attack since May, and the security vulnerability in the bridge protocol has once again become a fatal problem for the DeFi ecosystem.
(Background: Axelar cross-chain bridge hacked! Secret Network lost $4.67 million)
(Additional background: Cross-chain protocol ChainSwap was hacked, and more than 10 DeFi tokens crashed)

Cross-chain stablecoin bridge Allbridge Core suffered a flash loan attack on Sunday. The attacker used Kamino Finance to borrow 1.12 million USDC, then swapped USDC/USDT via rapid swaps to distort the exchange-rate mechanism for the stablecoin_pool_ within the bridge protocol. They ultimately withdrew $1.65 million in liquidity at a distorted price. After repaying the loan, their net profit was about $0.53 million.

This is at least the 6th bridge attack since May, coming right after Secret Network’s $4.67 million loss via the Axelar bridge and Taiko’s $1.7 million theft. Because bridge protocols lock large amounts of collateral tokens on the source chain, they become a favorite target for hackers. Allbridge’s repeated exploitation (in April 2023, on BNB Chain, it was also hit by the same flash-loan-and-price-manipulation method, costing $573,000) indicates that its smart contract vulnerabilities may never have been fully patched.

According to an on-chain analyst, 0x_Benav, who outlined the attack flow: after borrowing 1.12 million USDC from Kamino Finance, the attacker did not transfer funds directly to Allbridge. Instead, they first rapidly swapped USDC and USDT within the pool. Because Allbridge Core’s stablecoin pool relies on real-time price oracles, frequent swapping caused the system’s quoted price to deviate instantaneously from the true exchange rate. The attacker then withdrew large amounts of liquidity again using this temporary positive arbitrage window, repaid the original loan, and kept the difference.

Allbridge Core then posted an emergency announcement on X stating that it would suspend the operation of the entire protocol and called on all liquidity providers to withdraw funds immediately. The announcement also urged that if anyone had used this arbitrage window, they should consider returning the funds to compensate the affected LPs. However, the attacker has already bridged the stolen funds from Solana to Ethereum and moved them into a mixing pool within a privacy protocol, greatly increasing the difficulty of tracking.

Bridge protocol: a fragile link repeatedly exploited

Bridge security is no longer news. Because bridge protocols must lock tokens on the source chain and mint equivalent wrapped tokens on the destination chain, the escrow pools in the middle can often reach hundreds of millions of dollars, making them a treasure trove for hackers. Worse still, most bridge protocols have high logic complexity and are deployed across multiple chains, expanding the attack surface far beyond that of a single DeFi protocol.

In June, Ethereum Layer2 Taiko’s bridge protocol was stolen $1.7 million. Users were forced into emergency withdrawals, and the team spent 11 days and a four-phase recovery plan to restart bridging, while also covering user losses out of pocket. Earlier in May, Secret Network lost $4.67 million due to an unlimited minting vulnerability on the Axelar bridge. It was forced to immediately cut off connectivity with Axelar and later announced that it would migrate the entire ecosystem to Arbitrum.

According to a quick roundup by the crypto news account HIT, since last year, bridge attacks have totaled losses of hundreds of millions of dollars, and many can be traced back to the same kind of attack pattern—flash loans combined with price manipulation. This means that as long as the bridge protocol’s exchange-rate manipulation mechanism has a vulnerability, the same attack script can be replayed across different protocols.

Allbridge’s old flaw: it was hit by a flash loan attack as far back as 2023

What’s especially concerning is that Allbridge is not the first time it has been targeted. In April 2023, the protocol’s BNB Chain pool was hit by a flash loan attack, resulting in losses of $573,000 (290,000 BUSD plus 290,000 USDT). The attack pattern from then was almost identical to this week’s incident: the attacker simultaneously played the roles of liquidity provider and swapper, using a smart contract vulnerability to manipulate the swap price.

This suggests that the Solana deployment being hit this time likely involved the same unpatched smart contract vulnerability being exploited again. Cross-chain bridge attackers have long favored old vulnerabilities in new deployments: when developers expand to multi-chain setups, it’s easy to miss security patches, while hackers scan deployed instances one by one.

SOL-0.25%
USDC-0.01%
ETH0.14%
WAXL1.23%
KMNO-0.59%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned