Allbridge Core has paused operations after an attacker manipulated a USDC-USDT liquidity pool on Solana and extracted more than $1.1 million. The protocol suspended activity while investigati
Allbridge Core has paused operations after an attacker manipulated a USDC-USDT liquidity pool on Solana and extracted more than $1.1 million. The protocol suspended activity while investigating the incident and assessing losses suffered by liquidity providers. Blockchain security firm PeckShield estimated that approximately $1.65 million was affected and tracked the stolen assets as they moved from Solana to Ethereum. Allbridge officially confirmed the security incident and paused Core as a precaution while its team investigated the affected liquidity pools.
- Allbridge paused Core following the security incident.
- The final amount lost has not been officially confirmed.
- The project has not announced when normal operations will resume.
- Details about affected liquidity providers remain undisclosed.
- A technical postmortem and compensation plan are still pending.
Attacker Used Kamino Flash Loan to Distort Pool Pricing
According to Onchain Lens, the attacker borrowed approximately $1.12 million USDC through a flash loan from Kamino Finance. The temporary capital was used to execute transactions that altered the balance between USDC and USDT in the targeted Allbridge pool. The distorted ratio allowed the attacker to remove liquidity under more favorable conditions before repaying the Kamino loan within the same transaction. Early on-chain estimates placed the remaining proceeds above $1.1 million.
The flash-loan amount should not be treated as the value stolen. It represents the temporary funding used to carry out the attack, while the attacker’s profit was the amount retained after the loan was repaid. Available evidence indicates that the incident originated in the pricing or liquidity calculations of the Solana pool. There is currently no confirmed indication that an attacker compromised Allbridge’s cross-chain messaging or transaction-validation system.
Price-dependent DeFi systems have faced similar manipulation risks, including a $10.8 million Blend Protocol exploit in which an illiquid collateral asset was temporarily inflated before funds were borrowed against the distorted valuation. The attack method differed from the Allbridge transaction, but both cases show how temporary market conditions can be used against automated protocol calculations. Allbridge has not disclosed which part of the Solana program failed or whether the weakness affected swaps, liquidity withdrawals or another pool function.
Stolen Funds Moved to Ethereum as Final Loss Remains Unclear
After the attack, the proceeds were moved away from the affected Solana pool and routed toward Ethereum. Some reports also indicate that part of the assets passed through privacy-focused services, potentially complicating recovery efforts. Cross-chain movement has also appeared in other recent incidents, including the Bonzo Lend oracle exploit, where part of the borrowed assets was transferred from Hedera to Ethereum after the attack. That comparison relates only to the movement of proceeds, as the protocols and underlying vulnerabilities were different.
Several figures have circulated because they appear to measure different stages of the incident. The approximately $1.12 million figure refers to the Kamino flash loan, while the amount above $1.1 million represents the attacker’s initially calculated proceeds. lookonchain estimate of roughly $1.65 million reflects the wider value associated with the exploit and subsequent fund movement. The incident should therefore not be described as a confirmed $2 million loss. Allbridge has not released an official accounting that supports that exact figure.
The protocol advised users to remove liquidity from affected pools while its investigation continued. However, it has not identified how many liquidity providers were affected, how much capital remained in the targeted pool or whether deployments on other networks faced similar exposure.
Smaller contract-level incidents have also continued across DeFi, including an on-chain attack involving Uniswap v4 Router04 that reportedly drained about $42,100. The incidents are not technically connected, but both demonstrate why the affected component must be identified before describing an exploit as a failure of an entire protocol. Allbridge previously suffered a flash-loan attack against its BNB Chain liquidity pools in April 2023. That incident also involved pool-price manipulation, but no evidence currently shows that the same code-level vulnerability was responsible for the latest Solana attack.
The main unresolved issues are the exact loss, the vulnerable program logic, the extent of liquidity-provider exposure and the protocol’s recovery plan. Allbridge will also need to explain what safeguards will be added before Core resumes normal operations.