Monday, 20 July 2026 · World
USD/EUR 0.875 USD/GBP 0.7439 USD/JPY 162.5 USD/CNY 6.781 All rates →
RSS
EUROS The World Financial Report
Nº 9 Monday, 20 July 2026 · World Edition
LATEST
Crypto

Allbridge Core pauses protocol after $1.65m exploit

EUROS Newsroom · 18h ago · 2 min read
Allbridge Core pauses protocol after $1.65m exploit

Cross-chain bridge Allbridge Core lost $1.65 million to a flash loan attack, highlighting the persistent security risks in decentralized finance routing.

Cross-chain bridge Allbridge Core has halted its operations after an attacker drained roughly $1.65 million from the protocol. Blockchain security firms PeckShield and CertiK confirmed the breach.

The exploit relied on a classic decentralized finance manipulation tactic. According to onchain analyst Onchain Lens, the attacker borrowed $1.12 million via a flash loan from Solana-based liquidity protocol Kamino. These borrowed funds were used to rapidly swap USDC for USDT, deliberately distorting the stablecoin liquidity pool ratios. This allowed the attacker to withdraw assets at artificially favorable rates before routing the stolen capital through privacy protocols.

The illicit funds did not remain on the Solana network. Analysts noted that the attacker bridged the stolen assets over to Ethereum, a standard move designed to complicate tracing and recovery efforts across distinct blockchain ledgers.

Lingering vulnerabilities in cross-chain infrastructure

For market professionals, this incident underscores the structural fragility that continues to plague cross-chain bridges. These protocols are essential for moving capital between isolated blockchains, making them high-value targets for sophisticated attackers. By utilizing flash loans—uncollateralized loans that must be repaid within a single transaction—bad actors can execute large-scale capital manipulation without needing significant upfront capital of their own.

The reliance on such mechanisms lowers the barrier to entry for exploits, creating an asymmetric risk environment for liquidity providers. When a bridge's underlying pools are manipulated, the resulting losses are absorbed entirely by the users who deposit their assets, rather than the protocol itself.

Allbridge has acknowledged the attack and immediately urged users to withdraw their remaining liquidity from the compromised pools. In a notable departure from standard recovery procedures, the team is appealing directly to market participants who may have profited from the exploit's aftermath.

"The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage of it, please consider returning funds to the address below — this will go directly toward compensating affected LPs," the team stated. Allbridge noted its goal is to "return all affected funds" to users.

However, relying on the voluntary return of arbitrage profits illustrates the limited recourse available to decentralized finance protocols following a security breach. Until cryptographic security standards outpace the speed of flash loan execution, bridge protocols remain exposed.