A cross-chain bridge protocol just got hit with a 1.65 million dollar flash loan attack — and it is the second time in three years. Allbridge Core paused all operations on Solana after an attacker manipulated stablecoin pool ratios using borrowed funds, exposing the same vulnerability class that has drained hundreds of millions from DeFi over the past decade.
By Priya Sharma | July 20, 2026
The Incident: How a Flash Loan Drained 1.65 Million in Minutes
Allbridge Core, a cross-chain protocol that lets users move stablecoins like USDC and USDT between blockchains without creating wrapped tokens, halted all operations on July 20 after an attacker stole roughly 1.65 million dollars from its Solana liquidity pools. The exploit was confirmed by blockchain security firms CertiK and PeckShield, which tracked the attack in real time.
Here is how the attack worked in plain English. The attacker borrowed 1.12 million dollars through a flash loan from Kamino, a Solana-based lending protocol. A flash loan is like borrowing money from a bank and returning it in the same second — if you do not return it, the whole transaction cancels out. The attacker used that borrowed money to rapidly swap between USDC and USDT inside Allbridge’s pools, intentionally throwing off the internal exchange rate. Once the pools were confused about the true ratio of assets, the attacker withdrew funds at favorable prices and bridged them to Ethereum before anyone could react.
Think of it like this: imagine someone buys up all the apples at a farmers market, making it look like apples are scarce, and then sells them back at inflated prices before the market organizers realize what happened. Except in DeFi, the entire process takes seconds, not hours.
Allbridge immediately paused the protocol and urged all liquidity providers to withdraw their funds from affected pools. The team also asked traders who profited from the temporary pricing imbalance to return funds so that liquidity providers could be made whole. The stolen assets were bridged to an Ethereum address and then split across multiple wallets, making recovery difficult.
Technical Post-Mortem: Why Pool Manipulation Keeps Working
The attack vector is brutally simple and depressingly familiar. Allbridge Core uses liquidity pools — shared pots of tokens that facilitate trades between different assets. The pools rely on internal formulas to set exchange rates based on the ratio of tokens currently in the pool. When a pool has equal amounts of USDC and USDT, the exchange rate is close to one-to-one. But if someone rapidly swaps large amounts back and forth, they can skew the ratio and create a pricing discrepancy.
This is exactly the same class of vulnerability that has plagued DeFi since 2020. Balancer, Beanstalk, and dozens of other protocols have fallen to flash loan manipulation over the years. The pattern is always the same: an attacker borrows a massive amount of capital with no upfront cost, uses it to distort a pool’s pricing mechanism, extracts value, and repays the loan — pocketing the difference.
Allbridge had already survived a similar attack in 2023 that drained roughly 650,000 dollars from its BNB Chain pools. At the time, the team said it recovered most of the funds and updated its liquidity and withdrawal calculations. The fact that the same protocol was exploited again using a related technique raises serious questions about whether the underlying architecture can ever be fully secured against this attack pattern.
- Attack type — Flash loan manipulation of stablecoin pool ratios
- Amount stolen — Approximately 1.65 million dollars
- Flash loan source — Kamino (Solana lending protocol), 1.12 million dollars borrowed
- Chain — Solana liquidity pools, funds bridged to Ethereum
- Response — Protocol paused, LPs told to withdraw, white hats contacted
- Previous incident — 2023 BNB Chain exploit, approximately 650,000 dollars stolen
Governance Impact: Trust Erodes in Cross-Chain Bridges
The Allbridge exploit is not just a technical failure — it is a governance crisis for the entire cross-chain bridge sector. Bridges remain the most exploited category in all of crypto, with cumulative losses measured in the billions over the past five years. Each new attack weakens the case that decentralized bridges can ever match the security of centralized exchanges for moving assets between chains.
Allbridge raised 2 million dollars in 2022 to expand its bridge and fund security audits. Despite those audits, the protocol has now suffered two flash loan attacks in three years. Liquidity providers who trusted the protocol with their stablecoins are once again facing losses, and the reputational damage may be irreversible. In DeFi, trust is the only collateral — once it is gone, liquidity leaves and does not come back.
The broader DeFi community is also watching closely. Several major protocols have been pushing to make bridges more resilient through multi-signature wallets, time-locked withdrawals, and real-time monitoring systems. But every time a bridge gets exploited, it validates the skeptics who argue that cross-chain architecture is fundamentally riskier than operating within a single blockchain.
TVL Shifts: Capital Flees Bridge Protocols
The impact on Allbridge’s total value locked was immediate. Following the exploit announcement, liquidity providers began pulling funds from the protocol’s remaining pools. While the exact TVL drop will not be clear for several days, the pattern is consistent with every major bridge exploit: users vote with their wallets, and the capital flight is swift.
This matters for regular investors because bridge TVL is a leading indicator of cross-chain liquidity. When bridges lose deposits, it becomes harder and more expensive to move stablecoins between blockchains. That means higher slippage for anyone trying to transfer funds from, say, Solana to Ethereum — and in some cases, transfers may not be available at all if pools are drained.
The broader DeFi market cap stands at approximately 67 billion dollars as of July 2026, with trading volume around 2.34 billion dollars over 24 hours, according to market data aggregators. That is a rounding error compared to the total crypto market capitalization of 2.27 trillion dollars. Every bridge exploit reinforces the perception that DeFi remains a small, fragile corner of the crypto ecosystem — one step forward, two steps back.
Long-Term Prognosis: Can Bridges Ever Be Safe?
The honest answer is that cross-chain bridges may never be as safe as operating within a single blockchain. The fundamental problem is that bridges must connect two systems that were not designed to communicate with each other. Every bridge design — from liquidity pools like Allbridge to lock-and-mint systems like Wormhole to optimistic verification layers — introduces its own trade-offs between speed, cost, and security.
For regular investors, the takeaway is simple: treat every bridge as a high-risk operation. Only transfer amounts you can afford to lose, use bridges that have been battle-tested by time (not just audits), and consider whether you really need to move assets between chains. In many cases, the answer is no — you can achieve the same investment goals on a single blockchain without exposing yourself to bridge risk.
As for Allbridge, the protocol faces a long road to recovery. The team must not only patch the vulnerability but also convince liquidity providers that the third time will be different. In a market where trust evaporates instantly and returns slowly — if at all — the odds are stacked against them. The next few weeks will determine whether Allbridge follows the path of protocols that recovered stronger, or joins the long list of DeFi projects that simply faded away after their second strike.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
second time in three years and they still had the same vulnerability class open. unreal. flash loan resistance should be table stakes for any bridge by 2026
1.12M borrowed from Kamino, manipulated the USDC/USDT ratio, bridged to ETH before anyone noticed. same playbook as the old bZx attacks. nothing new under the sun
second time in three years and they still didnt fix the pool ratio oracle. how hard is it to use a TWAP
1.12M flash loan from Kamino to drain 1.65M from Allbridge. the ROI on these attacks is insane, costs basically nothing to borrow
@Tomas literally this. flash loans are a free money printer if the pool math is even slightly off. CertiK audited Allbridge too lol
paused on Solana but funds already on Ethereum. classic. bridges need circuit breakers that actually trigger before the money leaves
the fact they bridged to Ethereum and split across wallets immediately tells me this was not some amateur. pro job all the way