Finst

Allbridge Core Pauses Protocol After $1.1 Million Exploit

The attack hit USDC/USDT liquidity on Solana and adds to a growing list of DeFi exploits. Allbridge has shut down the protocol and is now trying to recover the stolen funds.

Allbridge Core Pauses Protocol After $1.1 Million Exploit

Key Takeaways

  • Allbridge Core paused its protocol after more than $1.1 million was drained from stablecoin liquidity pools.
  • The Solana attack used a $1.12 million USDC flash loan and manipulated the USDC/USDT pool with a series of rapid swaps.
  • Allbridge has opened an investigation, asked users to return any profits they made, and says it wants to send affected funds back to victims.

Allbridge Core has paused its protocol after an attacker drained more than $1.1 million (€1 million) from the stablecoin liquidity pools. Blockchain tracker Onchain Lens said the exploit happened on Solana and is part of a wider run of DeFi exploits, which had already led to $57.8 million (€50.5 million) in losses in July 2026.

How the Attack Worked

Onchain Lens reported that the attacker took out a $1.12 million (€1 million) USDC flash loan through Kamino. That loan was then used to push Allbridge Core's USDC/USDT pool out of balance through a string of quick swaps. Once the pool was distorted, liquidity was withdrawn at inflated values, and the flash loan was repaid in the same transaction.

The tracker said that setup produced about $1.1 million (€1 million) in gains. Onchain Lens also said the stolen assets were later routed through privacy protocols to obscure the money trail. The largest single withdrawal was recorded at $2.24 million (€2 million) in USDC.

Allbridge Looks for Recovery

Allbridge shut down the protocol as a precaution and launched an investigation. The company said the imbalance briefly created an arbitrage opportunity for some traders and asked anyone who profited to return the gains. In its own statement, the developers said they want to "return all affected funds" to the victims.

The incident is particularly notable because Allbridge has faced a similar exploit before. In April 2023, the protocol was also hit by a flash loan exploit, this time on the BNB network, with losses of about $570,000 (€498,500).

Why This Matters

For European crypto readers, the case is another reminder of how exposed DeFi protocols still are when liquidity and pricing can be manipulated in a matter of moments. These attacks are not new, but the combination of flash loans, stablecoin pools, and fast arbitrage makes it difficult for protocols to react quickly enough. In response, developers are increasingly adding extra safeguards such as TWAP oracles, multiple price feeds, and circuit breakers. That trend is also visible in protocols trying to use stable liquidity more efficiently, including Uniswap and Spark.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.