Tuesday, 21 July 2026 · World
USD/EUR 0.8758 USD/GBP 0.7444 USD/JPY 162.5 USD/CNY 6.778 All rates →
RSS
EUROS The World Financial Report
Nº 10 Tuesday, 21 July 2026 · World Edition
LATEST
Crypto

Allbridge halts Solana pools after $1.65m flash loan exploit

EUROS Newsroom · 16h ago · 1 min read
Allbridge halts Solana pools after $1.65m flash loan exploit

Cross-chain protocol Allbridge has paused operations after a $1.65 million exploit, highlighting persistent security vulnerabilities in decentralized finance liquidity pools.

Allbridge Core has paused its cross-chain stablecoin protocol following a $1.65 million flash loan exploit targeting its Solana liquidity pools. Security firms CertiK and PeckShield confirmed the attack, which saw an attacker manipulate internal pool ratios to extract assets at favorable rates.

The attacker borrowed $1.12 million via a flash loan from the Solana lending protocol Kamino. By rapidly swapping USDC and USDT within the same transaction, the exploiter artificially distorted the pricing metrics of the Allbridge pools. This allowed the withdrawal of mispriced assets, which were subsequently bridged to an Ethereum address and dispersed across multiple wallets. It remains unclear how much of the stolen capital the attacker still controls.

For market participants, the incident underscores the structural vulnerabilities inherent in cross-chain bridges that rely on isolated liquidity pools rather than wrapped tokens. Allbridge facilitates the transfer of native stablecoins between blockchains that do not natively communicate. When an attacker targets these isolated pools, the capital is entirely exposed, unlike systems where risks might be distributed across larger decentralized networks.

The initial manipulation left the Allbridge Solana pools severely imbalanced, creating secondary arbitrage opportunities for other traders. Allbridge has asked those who profited from this pricing distortion to return the funds to compensate the liquidity providers who suffered losses. Such requests are common in decentralized finance but rely entirely on voluntary compliance, leaving providers at a structural disadvantage.

This is the second time Allbridge has suffered a flash loan attack. A similar exploit in 2023 drained roughly $650,000 from its BNB Chain pools. Although the firm stated it recovered most of those funds and overhauled its liquidity and withdrawal calculations, this repeat failure raises serious questions about the effectiveness of its internal controls. The company raised $2 million in 2022 specifically to expand its bridge operations and fund security audits. For institutional users and investors, the repeated breaches highlight the difficulty of securing cross-chain infrastructure against sophisticated, low-capital attacks that require no upfront collateral.