On July 20, 2026, cross-chain bridge protocol Allbridge Core lost approximately $1.65 million after an attacker manipulated its stablecoin pool with a flash loan. Allbridge paused the protocol and urged liquidity providers in affected pools to withdraw funds immediately.
Key Takeaways
- Allbridge Core, a cross-chain stablecoin bridge, lost roughly $1.65 million, per PeckShield, after an attacker manipulated its liquidity pool with a flash loan.
- The attacker reportedly used a $1.12 million flash loan of USDC from Solana lending protocol Kamino, then swapped USDC and USDT to distort the pool’s exchange rate.
- Allbridge paused the protocol, urged liquidity providers to withdraw, and asked arbitrageurs who profited from the imbalance to voluntarily return funds.
- The attacker bridged the stolen funds from Solana to Ethereum and, per Coinpedia, routed them through privacy-focused infrastructure, complicating recovery.
- Solana’s price showed little reaction, trading near $76.66, up 1.06% on the day.
What Happened?
Allbridge Core was exploited for approximately $1.65 million early Monday, according to PeckShield. The team confirmed the incident within hours in a statement on X.
Allbridge Core is experiencing a security incident.
— Allbridge (@Allbridge_io) July 19, 2026
We have paused the protocol as a precaution while we investigate.
If you have liquidity in affected pools, please withdraw now.
The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage… pic.twitter.com/Ovg7yT35SM
Its goal is to return all affected funds to users, per Allbridge’s own statement. The team also asked traders who benefited from the temporary price distortion to send the money back voluntarily.
The attacker bridged the stolen funds from Solana to Ethereum shortly afterward. On-chain analysts say the funds were then routed through privacy-focused infrastructure that could make recovery harder..
Inside the Flash Loan: Borrow, Manipulate, Withdraw, Repay
The mechanism Allbridge Core faced, per Coinpedia’s on-chain analysis, involved no leaked key and no conventional bridge bug. Instead, the attacker reportedly took a $1.12 million flash loan of USDC from Solana lending protocol Kamino without posting collateral, then repeatedly traded USDC and USDT inside Allbridge Core’s stablecoin pool to distort its internal exchange rate math.
With the pool artificially imbalanced, the attacker withdrew liquidity at the manipulated rate, repaid the flash loan within the same transaction, and kept the difference as profit. A single withdrawal in the sequence was reportedly worth around $2.24 million before the attacker’s net take settled near the reported total.
The entire sequence fits inside one atomic transaction, leaving no window to intervene.
A Familiar Flaw and a Legal Gray Area
An analyst described the incident as a classic flash loan price manipulation attack, a vulnerability pattern that has affected DeFi protocols since 2020, arguing that the pool effectively trusted its own manipulable balances to determine pricing. Pricing a pool off its own internal balances, instead of an external feed, is a known risk design choice.
This is not the only time a DeFi bridge has shipped this design, a recurring flaw industry-wide.
Allbridge’s request that arbitrageurs return manipulated rate profits also sits in a gray area. Nothing legally compels a trader who exploited a pricing error to return it. The framing recasts a beneficiary as a good-faith actor, not someone facing a claim.
Implications for Cross-Chain DeFi
Solana traded at $76.66, gaining 1.06% over 24 hours on volume of $1.43 billion, suggesting the token market absorbed the news without much stress. The bigger risk sits with bridge confidence.
Headlines like this push liquidity providers to pull cross-chain funds broadly. Analysts flagged that the episode could pressure bridge-related total value locked if it triggers withdrawals from other Solana-based bridges.
The privacy-routing detail matters for regulatory enforcement tracking how bridge hacks get resolved. Once stolen stablecoins move through privacy infrastructure, tracing and freezing them gets harder than a typical bridge-hack recovery.
CoinLaw’s Takeaway
This Allbridge Core exploit, which drained roughly $1.65 million, reads as a design failure, not bad luck. A pool that prices trades off its own balances hands an attacker with enough borrowed capital the ability to set its own exchange rate for a few seconds, cash out, and repay the loan before anyone can react.
That flaw is a well-documented class of attack in decentralized finance, not a novel exploit. That a live cross chain bridge still let a pool price trades off its own manipulable balances is what matters here, more than the size of this single loss.
The legal framing Allbridge is using, asking arbitrageurs to voluntarily return manipulated rate profits, is a soft remedy for a hard problem. It works only if the people who benefited feel enough goodwill or reputational pressure to comply. If they don’t, Allbridge has little practical recourse beyond whatever it can trace before the funds disappear into privacy tools, which is close to the scenario now playing out on the Ethereum side.