Allbridge Core Pauses Operations Following $1.65M Exploit!



​Cross-chain vulnerabilities are back in the spotlight. Allbridge, the team behind the stablecoin bridge Allbridge Core, has officially paused its protocol following a sophisticated exploit that drained $1.65 million from its Solana deployment.

​The Flash Loan Attack
According to on-chain tracking from Onchain Lens, the attacker initiated a $1.12 million USDC flash loan from the Solana-based protocol Kamino. They then executed rapid USDC/USDT swaps to artificially distort the exchange rate within Allbridge Core's stablecoin pool.

​The Getaway
By withdrawing liquidity at these manipulated rates, the attacker repaid the initial loan and pocketed the difference. The stolen funds were quickly bridged from Solana over to Ethereum and deposited into privacy pools to obscure their trail.

​Protocol Paused
Allbridge immediately halted the protocol as a precaution, urging users with liquidity in the affected pools to withdraw. The team has publicly asked the attacker (and any opportunistic arbitrageurs) to return the funds so they can be used to compensate affected liquidity providers.

​A Recurring Nightmare
Shockingly, this isn't Allbridge's first run-in with this type of exploit. In April 2023, the protocol lost $573,000 to a near-identical flash loan attack on the BNB Chain. Furthermore, this marks at least the sixth major attack targeting a cross-chain bridge since May.
#allbridges
SOL0.16%
USDC0.00%
KMNO-2.49%
ETH1.19%
BNB0.22%
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 4
  • Repost
  • Share
Comment
Add a comment
Add a comment
QuantAuntie
· 11h ago
Attacked twice using the same method—should we doubt Allbridge’s technical and audit capabilities? How can user funds be kept safe?
View OriginalReply0
FloorSweeper
· 12h ago
Another flash loan—when will the cross-chain bridge security vulnerability finally be patched?
View OriginalReply0
PositionManager
· 12h ago
The attacker’s tactics were very seasoned; a 1.12 million USDC flash loan was used to leverage 1.65 million, generating a $500k profit, and then the funds were laundered through a privacy pool—this arbitrage move is truly textbook-level.
View OriginalReply0
IndicatorTuner
· 12h ago
Most ironically, last year they were just hacked for 570k, and this time they directly tripled that—looks like they didn’t learn their lesson at all. Users, withdraw your funds quickly—don’t wait for the third time.
View OriginalReply0
  • Pinned