TLDR
- Allbridge Core was exploited for $1.65 million on Sunday via a flash loan attack on its Solana deployment
- The attacker used a $1.12M USDC flash loan from Kamino to manipulate stablecoin pool exchange rates
- Stolen funds were bridged from Solana to Ethereum and moved into privacy pools
- Allbridge has paused the protocol and urged users to withdraw from affected pools
- This is at least the sixth cross-chain bridge attack since May 2026
Allbridge Core, a cross-chain stablecoin bridge, was exploited for roughly $1.65 million on Sunday. The team paused the protocol and is urging users to withdraw liquidity from affected pools.
Allbridge(@Allbridge_io) was exploited for ~$1.65M!
The exploiter quickly bridged all the stolen funds from #Solana to #Ethereum and swapped them for $ETH.https://t.co/9nSNCarACRhttps://t.co/Gl4p4U3XhL pic.twitter.com/3T5N0Tc8xt
— Lookonchain (@lookonchain) July 20, 2026
The attack targeted Allbridge Core’s Solana deployment. Blockchain security firms PeckShield and CertiK both flagged the incident shortly after it occurred.
How the Attack Worked
According to onchain analysts at Onchain Lens, the attacker took out a $1.12 million USDC flash loan from Kamino, a Solana-based liquidity protocol.
The attacker then rapidly swapped USDC for USDT, which distorted the exchange rate within Allbridge Core’s stablecoin pool. This created an imbalance that allowed the attacker to withdraw funds at manipulated rates.
After repaying the $1.12 million flash loan, the attacker kept the difference — totalling around $1.65 million. The stolen funds were then bridged from Solana to Ethereum and moved into privacy pools to obscure the trail.
Allbridge posted a warning on X, saying: “If you took advantage of it, please consider returning funds — this will go directly toward compensating affected LPs.”
Not the First Time
This is not Allbridge’s first flash loan exploit. In April 2023, the protocol was hit for $573,000 on the BNB Chain. In that attack, the exploiter acted as both a liquidity provider and swapper, draining nearly $290,000 in Binance USD and $290,000 in USDT.
The latest incident is part of a broader pattern of cross-chain bridge attacks. Since May, at least six bridges have been targeted.
In June, Ethereum layer-2 network Taiko had $1.7 million stolen from one of its bridge protocols. It paused and later reopened the bridge after an 11-day recovery process.
Weeks before that, Secret Network was hit by an “infinite mint” bug on a vulnerable smart contract. The flaw created unbacked versions of Axelar-wrapped assets, resulting in a $4.67 million loss.
Other recently exploited bridges include Gravity Bridge, Verus Bridge, and the Butter Network.
Cross-chain bridges are frequent targets because they hold large pools of funds that back bridged assets on destination blockchains. Allbridge Core’s team says its goal is to return all affected funds to users, and the investigation is ongoing.







