DeFi

Allbridge Halts Cross-Chain Protocol After $1.65M Flash Loan Attack on Solana Pools

Allbridge has suspended its Core cross-chain protocol after an attacker used a $1.12 million Kamino flash loan to distort Solana stablecoin pool pricing and drain roughly $1.65 million, which was then bridged to Ethereum.

⏱ 3 min read DeFi
Quick Summary
  • An attacker borrowed $1.12 million via a Kamino flash loan to manipulate Allbridge Core's Solana stablecoin pool pricing, stealing roughly $1.65 million in total before bridging the proceeds to Ethereum.
  • Allbridge has paused the protocol, urged liquidity providers to withdraw, and is asking traders who profited from the resulting arbitrage window to return funds to compensate affected LPs.
  • This is Allbridge's second flash loan exploit after a $573,000 attack on its BNB Chain pools in April 2023; more than $840 million has been lost to DeFi hacks in the first five months of 2026.

Cross-chain bridge Allbridge has suspended its Core protocol after an attacker drained approximately $1.65 million from its Solana stablecoin liquidity pools using a flash loan exploit, according to blockchain security firms PeckShield and CertiK, as well as the project itself.

How the Attack Unfolded

According to CertiK, the attacker borrowed $1.12 million through a flash loan from Kamino, a Solana-based lending protocol. Those borrowed funds were then used to execute a rapid series of stablecoin swaps that distorted the internal pricing mechanism Allbridge Core relies on to value assets within its pools.

With the pools mispriced, the attacker swapped just a few thousand dollars of USDT for roughly $2.24 million in USDC at the manipulated rate. The proceeds were then bridged from Solana to an Ethereum address before being scattered across multiple wallets. PeckShield confirmed the cross-chain transfer and flagged the Ethereum address: 0x651591b68A9c9650FB23F642162353306281ffDe.

It is not yet clear how much of the stolen funds remains traceable or recoverable.

Allbridge’s Response

The Allbridge team announced it had ‘paused the protocol as a precaution’ while investigating the incident and urged liquidity providers to withdraw funds from affected pools immediately.

The attack also created a brief arbitrage opportunity, as the pool imbalance allowed other traders to buy mispriced assets cheaply. Allbridge described this as a ‘temporary positive arbitrage window’ and asked anyone who profited from it to return the funds to a designated address, stating the money would ‘go directly toward compensating affected LPs.’ The team said its ‘goal is to return all affected funds.’

In a subsequent post, Allbridge said it was ‘preparing a detailed breakdown’ and post-mortem report, adding: ‘There is no threat to users liquidity right now.’ The project said it intends to relaunch Core without liquidity pools.

Not the First Time

This is the second flash loan attack Allbridge has suffered. In April 2023, a similar exploit drained around $573,000 from its BNB Chain pools. Following that incident, the project said it recovered most of the stolen funds and revised its approach to calculating liquidity and withdrawals. Allbridge had previously raised $2 million in 2022 to expand the bridge and fund security audits.

Cross-chain bridges and the liquidity pools supporting them have long been a primary target across DeFi. More than $840 million was lost to DeFi exploits in just the first five months of 2026. Last month, a bridge between Axelar and Secret Network was drained of $4.67 million after attackers exploited an ‘infinite mint’ vulnerability in a custom token contract.

Whether Allbridge can recover a significant portion of the $1.65 million will depend on tracing the bridged funds and whether arbitrage traders choose to return the profits they captured during the imbalance window.

⚖️ Our Verdict 📉 Bearish Signal

A repeat flash loan attack draining $1.65 million from Allbridge's Solana pools forces a protocol shutdown and raises fresh questions about cross-chain bridge security. The mitigants: Allbridge says there is no ongoing threat to user liquidity, is working to trace and claw back the funds, and recovered most of the losses after a similar 2023 exploit, though a second breach of the same kind will test confidence in its relaunched, pool-free design.