Allbridge halts Core after $1.65 million Solana pool exploit
Allbridge said it paused Core after security firms traced a flash-loan exploit that drained Solana stablecoin pools and moved funds to Ethereum.
By Sofia Marchetti · Columnist
· 3 min read
Allbridge has paused its Core cross-chain bridge after an attacker drained about $1.65 million from stablecoin liquidity pools on Solana, according to Allbridge and blockchain security firms. For everyday crypto users, the incident is a reminder that bridge protocols can carry smart-contract and pricing risks even when the assets involved are stablecoins.
Allbridge said Sunday on X that Core was experiencing a security incident and that it had stopped the protocol while it investigated. The project told liquidity providers, meaning users who supply tokens to pools so others can trade or bridge assets, to withdraw from affected pools.
A cross-chain bridge is a service that lets users move value between blockchains that do not directly communicate with each other. Allbridge Core uses pools of native stablecoins, including USDC and USDT, instead of issuing wrapped tokens, according to the project description cited in the report.
That design depends on pool pricing working as intended. Security firm CertiK said the attacker used a flash loan, a type of decentralized finance loan that is borrowed and repaid within one blockchain transaction, to manipulate how Allbridge’s pools valued assets.
How the exploit worked
PeckShield first flagged the incident on X and estimated the loss at roughly $1.65 million. Allbridge later confirmed PeckShield’s figure, according to the report, and PeckShield said the attacker moved the funds from Solana to Ethereum.
CertiK said the attacker borrowed $1.12 million from Kamino, a lending protocol on Solana, through a flash loan. The attacker then made a fast sequence of stablecoin swaps that distorted Allbridge’s internal accounting, which the pools use to price assets.
Once that pricing was thrown off, the attacker was able to pull assets from the pools at favorable prices and bridge the proceeds to Ethereum, according to CertiK’s explanation. In plain terms, the exploit did not require holding borrowed funds for long. The borrowed capital was used to temporarily push the system into a bad price state, extract value, and complete the transaction.
Allbridge said the pool imbalance also created a short-lived arbitrage opportunity. Arbitrage means profiting from price differences between markets or pools. The project asked traders who benefited from that imbalance to return funds.
What Allbridge says comes next
In follow-up posts on X, Allbridge said its team was preparing a detailed breakdown and a post-mortem report. The project also said, “There is no threat to users liquidity right now,” while it works on relaunching Core without liquidity pools.
Allbridge has not yet published the full post-mortem. Until then, the public timeline rests on statements from Allbridge and the on-chain analysis shared by PeckShield and CertiK.
The incident adds to a long-running security concern in decentralized finance: bridges concentrate liquidity across chains, which can make them attractive targets. In this case, the reported weakness centered on pool pricing during a flash-loan-driven sequence of swaps, according to CertiK.
This story draws on original reporting from Decrypt.