# Allbridge Core pauses after $1.65M flash-loan exploit

> Allbridge paused Core on July 19 after an attacker used a $1.12M Kamino flash loan to skew Solana USDC/USDT pools and drain about $1.65M, then bridge funds to Ethereum.

- **Source:** https://ptycoin.com/en/posts/2026-07-21-allbridge-core-165m-flash-loan-exploit/
- **Published:** 2026-07-21
- **Category:** News
- **Author:** Mateo
- **Tags:** security, defi, stablecoins, exchanges, self-custody

---


**Allbridge** paused its **Allbridge Core** cross-chain stablecoin bridge on **July 19, 2026** after an attacker drained roughly **$1.65 million** from Solana liquidity pools. Security firms [PeckShield](https://x.com/PeckShieldAlert/status/2079011150713561173) and [Onchain Lens](https://x.com/OnchainLens/status/2079000826178425126), as reported by [CoinDesk](https://www.coindesk.com/business/2026/07/20/cross-chain-protocol-allbridge-halts-after-usd1-65-million-flash-loan-exploit) and [Cointelegraph](https://lcx.com/en/cryptonews/allbridge-pauses-cross-chain-bridge-after-165m-exploit), say the raid used a **$1.12 million USDC flash loan** from [Kamino](https://kamino.finance/) to distort pool ratios, withdraw liquidity at manipulated rates, repay the loan in the same transaction, and keep the difference.

## What Allbridge said

In a [Sunday post on X](https://x.com/Allbridge_io/status/2078932561036722319), the team confirmed a security incident, said it had **paused the protocol as a precaution**, and told liquidity providers in affected pools to **withdraw now**. It also said the pool imbalance briefly opened a positive arbitrage window and asked traders who took that window to return funds to a published address so the money could go toward compensating affected LPs:

`0x01a494079DCB715f622340301463cE50cd69A4D0`

That voluntary-return ask is unusual but practical. Once a stable pool is skewed, anyone who can see the distortion can trade against it; the original attacker is not the only party who can end up with value that came from LP inventory.

A [follow-up post Monday](https://x.com/Allbridge_io/status/2079172437103526146) said the incident accelerated a transition the team had already planned: in about **three months**, Allbridge Core and Allbridge Classic will stop operating in their current form, with traffic moving toward **Allbridge Next**, which the project describes as newer infrastructure. LPs were told again to withdraw ahead of that sunset.

## How the drain worked

The public on-chain reconstruction is consistent across PeckShield, Onchain Lens, CoinDesk, CryptoPotato, and The Crypto Times:

1. Borrow about **$1.12 million USDC** from Kamino on Solana (no collateral, repaid in the same transaction).
2. Run rapid **USDC/USDT** swaps through Allbridge Core’s Solana pools to skew the stablecoin ratio.
3. Withdraw liquidity at the distorted rate, repay the flash loan, and pocket the residual.
4. Bridge the proceeds **from Solana to Ethereum**, convert toward ETH, and move some value into privacy pools to slow tracing.

The design detail that matters is simple. Allbridge Core holds **native stablecoin liquidity** on each chain so transfers can settle without wrapped-token wrappers. That is efficient for users and expensive when withdrawal pricing reads reserves that a single large swap just moved. [Immunefi](https://immunefi.com/) security lead Gonçalo Magalhães, quoted in [The Crypto Times](https://www.cryptotimes.io/2026/07/20/allbridge-core-hit-by-1-65m-solana-flash-loan-exploit-its-second-since-2023/), framed the failure mode as pools where imbalance is cheap and exit pricing still trusts those post-swap reserves: capital alone is enough.

## Second time for the same pattern

This is not Allbridge’s first flash-loan hit. In **April 2023**, Core lost about **$573,000** on BNB Chain when an attacker acted as both liquidity provider and swapper to manipulate prices (roughly half BUSD, half USDT), according to [CryptoPotato](https://cryptopotato.com/allbridge-pauses-protocol-after-1-65m-exploit-drains-stablecoin-liquidity-pools/) and contemporaneous coverage. Most of that haul was later returned under a white-hat arrangement.

A second pool-manipulation loss three years later is the uncomfortable part of the story. Safeguards added after 2023, including rebalancing authority meant to correct skewed pools, did not stop Sunday’s Solana drain. Recovery negotiations may still happen; history gives a template, not a guarantee, especially once funds have crossed chains and entered privacy tooling.

## Why bridges keep showing up on the list

Cointelegraph counts this as **at least the sixth cross-chain bridge attack since May**, after incidents including Taiko (~$1.7M), Secret Network / Axelar-wrapped assets (~$4.67M), Gravity Bridge, Verus Bridge, and Butter Network. Bridges concentrate assets that back transfers on the far side. One bad pricing assumption empties the float that makes the product useful.

Latin American users already route **dollar stablecoins** across chains for remittances, freelancing, and treasury moves. A Core-style pool is not “your wallet got hacked”; it is **LP inventory and bridge inventory** under program rules. If you provided liquidity, the loss path is pool math. If you only used the bridge as a customer and still hold assets in your own keys, the risk is downtime and incomplete routes while Core is paused, not an automatic key compromise. Self-custody still wins for long-term balances you control; it does not rewrite the risk of parking capital inside someone else’s AMM.

## What to watch

- **Whether any of the stolen ETH lands on exchange deposit addresses** that can freeze inflows (on-chain trackers are watching).
- **Voluntary returns** to Allbridge’s published address, and whether the team later posts a full loss and compensation accounting.
- **The Allbridge Next migration**: product docs and LP withdrawal deadlines over the next three months, not marketing slides.

If you still have liquidity in affected Allbridge Core pools, treat the team’s own instruction as the operational fact: withdraw while you can. Pause notices and status posts are part of the product risk, not a footnote. Not financial advice.

---

Source: PTYcoin — https://ptycoin.com/en/posts/2026-07-21-allbridge-core-165m-flash-loan-exploit/. Free to read and cite with attribution to ptycoin.com. AI-usage terms: https://ptycoin.com/en/ai-usage/
