BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Allbridge Core exploited for $1.65 million, attacker moves funds to Ethereum

Allbridge Core, a cross-chain protocol that facilitates stablecoin transfers across different blockchains, experienced a security breach that resulted in a loss of $1.65 million from its Sola

AnonymousCryptoCompass newsroom
July 20, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

Allbridge Core, a cross-chain protocol that facilitates stablecoin transfers across different blockchains, experienced a security breach that resulted in a loss of $1.65 million from its Solana deployment. The incident led to an immediate halt of all protocol operations as teams began an investigation into the cause and scope of the exploit.

Flash loan exploit hits Solana pools

The attack took place on Allbridge’s Solana-based stablecoin bridge and was quickly confirmed by the project team. Allbridge paused activity as security teams and independent blockchain investigators began reviewing the incident’s impact.

According to research from blockchain analytics firm Lookonchain, the attacker bridged all stolen assets to Ethereum at high speed before converting them into ETH. These rapid transfers complicated fund recovery and underscored the fast-moving nature of cross-chain exploits.

Allbridge halted operations after a $1.65 million exploit targeted its Solana pools, with the attacker immediately moving the stolen funds to Ethereum and converting them into ETH, raising concerns about ongoing security risks in cross-chain protocols.

Further blockchain analysis revealed that the attacker initiated the exploit by using a flash loan of $1.12 million in USDC, borrowed from Kamino, a Solana liquidity protocol. By carrying out several transactions within a single block, the attacker temporarily swapped USDC and USDT tokens, manipulating the exchange rate within Allbridge Core’s stablecoin pool.

This price manipulation allowed the attacker to withdraw more stablecoins than were initially supplied, generating significant profits without retaining the borrowed funds for long. After the flash loan was repaid, the attacker kept the proceeds, which investigators estimate at around $1.65 million. The attacker then attempted to conceal the funds via Ethereum-based privacy channels.

Allbridge urged liquidity providers in affected pools to withdraw their funds while investigations continue. The protocol also called on users who profited from temporary arbitrage opportunities related to the attack to voluntarily return the funds, aiming to compensate liquidity providers who sustained losses.

Mini dictionary: Flash loan — a type of uncollateralized loan that allows users to borrow large amounts of funds within a single blockchain transaction, often used for arbitrage or, in some cases, to exploit vulnerabilities in protocols.

Security concerns for cross-chain bridges intensify

This exploit is not the first security incident for Allbridge. The protocol previously experienced a flash loan attack in 2023, which resulted in losses surpassing $573,000, this time on its BNB Chain deployment. Both episodes involved attackers manipulating swap prices within liquidity pools.

Cross-chain bridges like Allbridge remain attractive targets due to the large sums of liquidity they handle to facilitate asset transfers between independent blockchains. Successful attacks often cause major financial damage in a short amount of time and across multiple networks.

Bridge projectYear of major breachReported lossAllbridge (Solana)2026$1.65 millionAllbridge (BNB Chain)2023$573,000Taiko2026Not disclosed

In recent months, additional bridge platforms such as Taiko, Secret Network, Gravity Bridge, Verus Bridge, and Butter Network have faced similar security breaches. These incidents have put a spotlight on the importance of thorough smart contract audits, robust monitoring mechanisms, and improved liquidity protection for decentralized finance systems.

Blockchain security groups, including PeckShield and CertiK, quickly identified the Allbridge exploit just after abnormal on-chain activity was detected. Investigators are still analyzing transaction histories to fully map the attack and support possible fund recovery.

The investigation continues as Allbridge assesses potential security upgrades and seeks to address potential reimbursement for those affected. The repeated incidents underline the persistent challenges faced by cross-chain infrastructure despite advances in decentralized finance platform security.

The post Allbridge Core exploited for $1.65 million, attacker moves funds to Ethereum appeared first on COINTURK NEWS.