Futures
Access hundreds of perpetual contracts
CFD
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
CFD
Stock CFD Derivatives
US Stocks
Access real US stocks and ETFs
HK Stocks
Trade quality Hong Kong-listed stocks
Korean Stocks
SK Hynix
Real Korean stocks and top assets
Stock Futures
High leverage, 24/7 trading
Tokenized Stocks
Backed by real stock assets
IPO Access
Unlock full access to global stock IPOs
GUSD
3.8%
Mint GUSD for Treasury RWA yields
Stocks Activities
Trade Popular Stocks and Unlock Generous Airdrops
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
Pre-IPOs
Unlock full access to global stock IPOs
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Promotions
AI
Gate AI
Your all-in-one conversational AI partner
Gate AI Bot
Use Gate AI directly in your social App
GateClaw
Gate Blue Lobster, ready to go
Gate for AI Agent
AI infrastructure, Gate MCP, Skills, and CLI
Gate Skills Hub
10K+ Skills
From office tasks to trading, the all-in-one skill hub makes AI even more useful.
Another incident for the cross-chain bridge! Allbridge Core suffers a flash loan attack, losing $1.65 million
Cross-chain stablecoin bridge Allbridge Core’s Solana deployment was hit by a flash loan attack. After the attacker borrowed $1.12 million in USDC, they rapidly swapped to distort the bridge protocol’s stablecoin_pool_ exchange-rate mechanism, then arbitraged $1.65 million. The stolen funds were bridged to Ethereum and flowed into a privacy pool. This is the 6th cross-chain bridge attack since May, and the security vulnerability in the bridge protocol has once again become a fatal problem for the DeFi ecosystem.
(Background: Axelar cross-chain bridge hacked! Secret Network lost $4.67 million)
(Additional background: Cross-chain protocol ChainSwap was hacked, and more than 10 DeFi tokens crashed)
Cross-chain stablecoin bridge Allbridge Core suffered a flash loan attack on Sunday. The attacker used Kamino Finance to borrow 1.12 million USDC, then swapped USDC/USDT via rapid swaps to distort the exchange-rate mechanism for the stablecoin_pool_ within the bridge protocol. They ultimately withdrew $1.65 million in liquidity at a distorted price. After repaying the loan, their net profit was about $0.53 million.
This is at least the 6th bridge attack since May, coming right after Secret Network’s $4.67 million loss via the Axelar bridge and Taiko’s $1.7 million theft. Because bridge protocols lock large amounts of collateral tokens on the source chain, they become a favorite target for hackers. Allbridge’s repeated exploitation (in April 2023, on BNB Chain, it was also hit by the same flash-loan-and-price-manipulation method, costing $573,000) indicates that its smart contract vulnerabilities may never have been fully patched.
According to an on-chain analyst, 0x_Benav, who outlined the attack flow: after borrowing 1.12 million USDC from Kamino Finance, the attacker did not transfer funds directly to Allbridge. Instead, they first rapidly swapped USDC and USDT within the pool. Because Allbridge Core’s stablecoin pool relies on real-time price oracles, frequent swapping caused the system’s quoted price to deviate instantaneously from the true exchange rate. The attacker then withdrew large amounts of liquidity again using this temporary positive arbitrage window, repaid the original loan, and kept the difference.
Allbridge Core then posted an emergency announcement on X stating that it would suspend the operation of the entire protocol and called on all liquidity providers to withdraw funds immediately. The announcement also urged that if anyone had used this arbitrage window, they should consider returning the funds to compensate the affected LPs. However, the attacker has already bridged the stolen funds from Solana to Ethereum and moved them into a mixing pool within a privacy protocol, greatly increasing the difficulty of tracking.
Bridge protocol: a fragile link repeatedly exploited
Bridge security is no longer news. Because bridge protocols must lock tokens on the source chain and mint equivalent wrapped tokens on the destination chain, the escrow pools in the middle can often reach hundreds of millions of dollars, making them a treasure trove for hackers. Worse still, most bridge protocols have high logic complexity and are deployed across multiple chains, expanding the attack surface far beyond that of a single DeFi protocol.
In June, Ethereum Layer2 Taiko’s bridge protocol was stolen $1.7 million. Users were forced into emergency withdrawals, and the team spent 11 days and a four-phase recovery plan to restart bridging, while also covering user losses out of pocket. Earlier in May, Secret Network lost $4.67 million due to an unlimited minting vulnerability on the Axelar bridge. It was forced to immediately cut off connectivity with Axelar and later announced that it would migrate the entire ecosystem to Arbitrum.
According to a quick roundup by the crypto news account HIT, since last year, bridge attacks have totaled losses of hundreds of millions of dollars, and many can be traced back to the same kind of attack pattern—flash loans combined with price manipulation. This means that as long as the bridge protocol’s exchange-rate manipulation mechanism has a vulnerability, the same attack script can be replayed across different protocols.
Allbridge’s old flaw: it was hit by a flash loan attack as far back as 2023
What’s especially concerning is that Allbridge is not the first time it has been targeted. In April 2023, the protocol’s BNB Chain pool was hit by a flash loan attack, resulting in losses of $573,000 (290,000 BUSD plus 290,000 USDT). The attack pattern from then was almost identical to this week’s incident: the attacker simultaneously played the roles of liquidity provider and swapper, using a smart contract vulnerability to manipulate the swap price.
This suggests that the Solana deployment being hit this time likely involved the same unpatched smart contract vulnerability being exploited again. Cross-chain bridge attackers have long favored old vulnerabilities in new deployments: when developers expand to multi-chain setups, it’s easy to miss security patches, while hackers scan deployed instances one by one.