The attacker allegedly relied on a flash loan and a series of rapid token swaps to manipulate the bridge’s stablecoin exchange rate.
Allbridge, the company behind the cross-chain stablecoin bridge Allbridge Core, said it has temporarily paused the protocol as a precaution following a “security incident” that reportedly resulted in the loss of $1.65 million on Sunday.
The incident impacted Allbridge Core’s Solana deployment, with the stolen funds reportedly bridged by the attacker from Solana to Ethereum before being transferred into privacy pools.
“Allbridge Core is experiencing a security incident,” the team said in a post on X on Sunday. “As a precaution, the protocol has been paused while the issue is being investigated. If you have liquidity in the affected pools, please withdraw it immediately.”
Flash Loan Attack Exploited Allbridge Core’s Stablecoin Pool#
The Allbridge Core exploit marks at least the sixth attack on a cross-chain bridge since May. Such bridges remain attractive targets for attackers because they typically hold large pools of funds that support bridged assets on the destination blockchain.
Onchain Lens reported that the attacker obtained a $1.12 million USDC (USDC) flash loan from Kamino before executing a series of rapid USDC-to-USDT swaps that allegedly manipulated the exchange rate within Allbridge Core’s stablecoin pool.
The attacker then withdrew liquidity using the manipulated exchange rates, repaid the $1.12 million USDC flash loan, and retained the remaining funds as profit.
“The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage of it, please consider returning funds… this will go directly toward compensating affected LPs,” .
Stay in the loop
Get crypto news before the market moves
Join thousands of investors who read our daily briefing.
No spam. Unsubscribe anytime.
This was not the first time Allbridge Core had been targeted by a flash loan attack.
In April 2023, Allbridge suffered a $573,000 exploit after a flash loan attack targeted its liquidity pool on the BNB Chain. The attacker operated as both a liquidity provider and a swapper, exploiting a smart contract vulnerability to manipulate swap prices, resulting in the theft of approximately $289,900 in Binance USD (BUSD) and $290,900 in USDt (USDT).
Cross-Chain Bridges Face Rising Attacks Since May#
In June, Ethereum layer-2 network Taiko urged users to withdraw their assets from its bridge protocols after attackers exploited one of the network’s bridges and stole approximately $1.7 million.
Taiko reopened its bridge 11 days later after successfully completing a four-step recovery plan.
Weeks before the Taiko incident, Secret Network suffered a $4.67 million exploit after attackers took advantage of an “infinite mint” vulnerability in a smart contract, creating unbacked versions of Axelar-wrapped assets.
Other recent bridge-related exploits have also targeted Gravity Bridge, Verus Bridge, and Butter Network.



