Allbridge has paused its flagship cross-chain stablecoin bridge, Allbridge Core, after an attacker drained roughly $1.65 million from its Solana deployment.
According to preliminary on-chain analysis, the attacker used a $1.12 million USDC flash loan from Kamino to manipulate the protocol’s USDC/USDT liquidity pool and withdraw funds at favorable rates before the pool could rebalance.
Sponsored
Crypto Prediction Markets
18+ · Gambling involves risk. Play responsibly.
The incident marks the second flash-loan-related exploit to affect Allbridge in three years. In April 2023, the protocol lost roughly $573,000 in an attack targeting its BNB Chain deployment.
While the two incidents occurred on different blockchains and under different conditions, their apparent similarities have prompted a question: is this a new vulnerability, or the same architectural flaw resurfacing on a different chain?
Comparing the 2023 and 2026 Exploits
The attacks targeted different blockchain environments, but available evidence suggests they shared several common characteristics.
In March 2023, Allbridge suffered a roughly $573,000 exploit on BNB Chain after an attacker manipulated the protocol’s liquidity pool pricing logic.
According to post-incident analyses, the attacker acted as both a liquidity provider and trader, swapping BSC-USD for BUSD to alter the pool’s balance before withdrawing liquidity at an artificially favorable rate. The attacker then repaid the flash loan and retained the profit generated by the temporary pricing distortion.
Preliminary analysis indicates the July 2026 Solana exploit appeared to follow a similar pattern.
The attacker reportedly borrowed $1.12 million in USDC through a flash loan from Kamino and executed a series of rapid USDC/USDT swaps that altered the pool’s internal ratio. The attacker then withdrew liquidity at inflated values before normal market activity could restore equilibrium, resulting in approximately $1.65 million in losses.
At a high level, both incidents appear to have involved manipulation of internally derived pool pricing immediately before liquidity withdrawals.
In systems that rely primarily on pool balances to determine value, sufficiently large same-block transactions can temporarily distort pricing faster than arbitrage traders or automated correction mechanisms can respond.
What Changed Between the Two Incidents?
Several factors differed between the 2023 and 2026 exploits.
Blockchain: The first exploit occurred on BNB Chain, while the latest incident affected Allbridge’s Solana deployment as the protocol expanded its multichain footprint.
Scale: The financial impact increased significantly, rising from roughly $573,000 in 2023 to approximately $1.65 million in 2026.
Fund movement: Following the 2023 exploit, stolen funds were traced to Tornado Cash. In the latest incident, blockchain investigators reported that funds were bridged from Solana to Ethereum before moving through privacy-focused infrastructure.
Recovery path: The 2023 case ultimately resulted in a white-hat arrangement that led to the recovery of roughly $465,000. In contrast, the 2026 exploit remains unresolved. Allbridge has issued a public appeal asking traders who profited during the resulting arbitrage window to voluntarily return funds, but no recovery has been confirmed.
Did Allbridge Address the Root Cause?
One of the key unresolved questions is whether the protocol’s response to the 2023 exploit addressed a specific implementation flaw or whether broader architectural risks remained.
There is currently no public evidence that the 2026 exploit resulted from the exact same code vulnerability identified in 2023. However, both incidents appear to involve temporary manipulation of liquidity pool pricing immediately before withdrawals were executed.
That similarity has prompted scrutiny of whether the attacks stem from isolated coding issues or from a pricing model that may be vulnerable to flash-loan-driven distortions under certain market conditions.
If future investigations determine that both exploits relied on similar economic assumptions rather than identical code flaws, the latest incident could point to a broader design challenge rather than a newly discovered vulnerability.
Why This Matters
The exploit comes amid a continuing wave of DeFi and bridge-related security breaches.
Blockchain security researchers estimate that crypto exploits generated approximately $57.8 million in losses during July 2026 alone, highlighting persistent risks across decentralized finance infrastructure.
For Allbridge, a second flash-loan-related exploit in three years is likely to renew scrutiny of how decentralized finance platforms protect liquidity pools from short-term price manipulation.
Delve into DailyCoin’s popular crypto news today:
Grayscale Rebrands Bitcoin Miners ETF Amid AI Computing Shift
Bitcoin Capitulation Is Cooling, But $69K Remains Key
DailyCoin’s Vibe Check: Which way are you leaning towards after reading this article?