Allbridge Core pause after reported $1.65M Solana exploit
Allbridge said it paused Allbridge Core after a reported $1.65 million incident affecting its Solana deployment; reporting indicated a flash-loan-driven stablecoin rate manipulation followed by onward bridging.
On 2026-07-20, Allbridge said it paused Allbridge Core after a reported security incident affecting its Solana deployment. Public reporting stated that $1.65 million was drained and attributed the loss to a flash-loan-assisted manipulation of the bridge’s stablecoin exchange rate, after which liquidity was reportedly withdrawn at distorted prices and funds were bridged onward to Ethereum and privacy pools. The immediate severity was limited in archive terms but material for the affected protocol. What is established from the present record is the protocol pause, the reported loss size, the affected deployment, and the operator’s withdrawal warning. What remains contested or incomplete includes attacker attribution, exact transaction-level execution, and whether any funds have been recovered as of 2026-07-20.
This post-mortem relied on the structured brief provided for the incident, which in turn cited public reporting from Cointelegraph and attributions within that report to Onchain Lens. The event timeline, entity list, unresolved questions, and comparative analytics were used to separate established facts from reported but not independently verified mechanism claims. Because the dossier did not include primary court filings, protocol post-mortems, transaction hashes, or contract-level forensic reports, a conservative verification standard was applied: operator statements were treated as direct claims, and exploit mechanics described by secondary reporting were framed conditionally.
Allbridge Core, a cross-chain stablecoin bridge operated by Allbridge, said on 2026-07-20 that it had paused the protocol as a precaution after what it described as a security incident.[1] The same reporting stated that the incident affected Allbridge Core’s Solana deployment and that the reported loss reached $1.65 million.[2][4] In the immediate response, Allbridge also said that users with liquidity in affected pools should withdraw immediately while the matter was investigated.[7]
The mechanism described in the available public record was not presented through a primary forensic report, but secondary reporting attributed the exploit to price manipulation within the bridge’s stablecoin exchange process.[3] Cointelegraph reported that the attacker allegedly used a flash loan and rapid swaps to manipulate the bridge’s stablecoin exchange rate.[3] The same report, citing Onchain Lens, stated that the flash loan was a $1.12 million USDC loan sourced from Kamino.[5] On the present record, this sequence suggests a transient distortion of pricing conditions rather than a conventional private-key compromise or direct contract drain, although the dossier does not provide transaction-level evidence sufficient to independently reconstruct each step.[3][5]
According to the same reporting, the alleged execution path proceeded from the flash loan into rapid swaps that changed the effective exchange conditions used by the protocol.[3] Once those rates had reportedly been manipulated, the attacker then withdrew liquidity at the distorted prices, repaid the $1.12 million USDC loan, and retained the difference.[5][6] In functional terms, the reported loss therefore appears to have depended on temporary balance-sheet asymmetry created within a single transaction flow or tightly coupled sequence, a pattern commonly associated with flash-loan-enabled market manipulation, though as of 2026-07-20 the dossier had not established the exact transaction hash, contract address, or full on-chain path.[5][6]
The incident was reported as specific to the Solana deployment of Allbridge Core rather than to all deployments or all chains supported by the protocol.[4] That distinction matters because the available account did not describe a generalized failure across the bridge’s entire architecture; instead, it localized the event to one deployment while the protocol operator paused the system as a precaution.[1][4] The brief also associated the event with two recurring structural lessons in the archive: centralized_validator_set and absence_of_withdrawal_monitoring. Those labels do not by themselves prove the immediate exploit path, but they indicate that the incident has been categorized within known bridge-risk and controls-failure patterns rather than as an isolated anomaly without precedent.
Reporting further stated that the stolen funds were bridged from Solana to Ethereum before moving into privacy pools.[1] In post-exploit analysis, such onward movement is usually relevant because it can complicate tracing and recovery, but the present dossier did not include the transaction identifiers needed to verify the route independently.[1] Nor did it establish whether the movement to Ethereum and privacy pools occurred in one continuous sequence or through intermediate addresses. As a result, the public record supports only a limited conclusion: the funds were reported to have left the affected Solana environment and to have been moved onward in a manner consistent with concealment or obfuscation efforts.[1]
The documented consequences were immediate but narrowly described. Allbridge paused Allbridge Core after the incident and publicly instructed liquidity providers in affected pools to withdraw.[1][7] The reported financial impact was $1.65 million.[2] No court filing, regulator statement, recovery announcement, or formal attribution was included in the dossier, and no user-loss count was established. On the available record, the material consequences therefore consisted of the reported drain from the Solana deployment, the precautionary halt of the protocol, and the operational disruption implied by the withdrawal warning and investigation status.[1][2][4]
Discussion
In archive context, this incident ranked #56 of 70 by severity, placing it in the 21.4th percentile across the full catalogue. Within the narrower set of hacks, it ranked #29 of 33. On loss size alone, it therefore sat in the lower tier of recorded crypto incidents, even though the event remained operationally significant for the affected protocol. The more analytically important feature was the vector. The archive recorded 2 prior flashloan events with cumulative $0.20B affected and mean recovery 100.0%; within that subset, 1 was fully recovered and 0 had low/no recovery. That comparison should be read cautiously because the sample is small, but it indicates that flash-loan incidents in the archive have not uniformly produced permanent losses. By contrast, the broader hack category contained 12 other records with mean recovery 91.6% and mean resolution 465 days, suggesting that even when immediate containment occurs, final disposition often extends well beyond the incident date. The pattern labels attached to this case were more recurrent than the vector itself. The archive had observed centralized_validator_set in 9 prior events, including 2 in the past 12 months. It had observed absence_of_withdrawal_monitoring in 20 prior events, including 15 in the past 12 months. That recurrence count places the incident within a familiar control-failure landscape: not among the archive’s largest losses, but aligned with repeatedly catalogued weaknesses in bridge operations and post-exploit containment. The wider archive context reinforces that point, with 73 total events catalogued and 42 in the 12 months preceding this incident.
Comparative analytics
All comparisons computed against the 73-event CryptoMortem archive at time of publication.
- Severity rank across full archive: #56 of 70 (21.4th percentile).
- Severity rank within same event type: #29 of 33.
- Attack vector "Flashloan": 2 prior events in archive, cumulative $203M, mean recovery 100.0%; 1 fully recovered, 0 with low or no recovery.
- Event type "Hack": 12 other records in archive, mean recovery 91.6%, mean resolution 465 days.
- Pattern "Centralized Validator Set": observed in 9 prior events (2 in the past 12 months).
- Pattern "Absence Of Withdrawal Monitoring": observed in 20 prior events (15 in the past 12 months).
- Archive context: 73 events catalogued; 42 in the 12 months preceding this incident.
Limitations
The present record was materially incomplete. The dossier did not establish attacker attribution. It also did not establish whether any funds were recovered. No transaction hash, contract address, or exact on-chain path was provided, which limited independent verification of the reported flash-loan sequence, the alleged rate manipulation, and the onward movement from Solana to Ethereum and privacy pools. The exact exploit timestamp was also not established beyond the publication date and the report’s reference to events occurring "on Sunday." In addition, the mechanism narrative depended on secondary reporting and an attributed Onchain Lens observation rather than on a primary protocol forensic report, audit memorandum, or court filing.
Timeline
- Security incident reported on Allbridge Core
Allbridge said it was experiencing a security incident and paused the protocol as a precaution.
source → - Users told to withdraw from affected pools
The company warned liquidity providers in affected pools to withdraw immediately while it investigated.
source → - Flash loan and swaps allegedly used
The attacker allegedly used a flash loan and rapid swaps to distort the bridge’s stablecoin exchange rate.
source → - Kamino flash loan reported
Onchain Lens reported a $1.12 million USDC flash loan from Kamino.
source → - Funds allegedly bridged onward
The article says the stolen funds were bridged from Solana to Ethereum before moving into privacy pools.
source → - Allbridge pauses Core after $1.65 million flash loan attack
Allbridge said it paused the protocol as a precaution while investigating the security incident and urged liquidity providers to withdraw from affected pools. The team said it is preparing a detailed breakdown and post-mortem, and wants to relaunch Core without liquidity pools.
source → - Attacker bridged stolen funds from Solana to Ethereum
Security firms PeckShield and CertiK flagged that the attacker has bridged the stolen funds from Solana to Ethereum. The report follows Allbridge Core’s pause after the reported $1.65 million flash loan exploit.
source → - Allbridge Core pauses after $1.65 million exploit
Allbridge Core halted its protocol after an attacker drained roughly $1.65 million from its Solana liquidity pools using a $1.12 million flash loan from Kamino. The company told liquidity providers to withdraw from affected pools and asked traders who profited from the imbalance to return funds for LP compensation.
source →
Who was involved
- Ethereumnetworkbystander
- Kaminoprotocolbystander
- Solananetworkbystander
- Allbridge Coreprotocolvictim$1.6M
Structural failures identified
Sources
- Allbridge pauses cross-chain bridge after $1.65M exploit, Cointelegraph — Protocol pause, reported loss size, Solana deployment impact, flash-loan/swaps allegation, Kamino reference, and onward movement to Ethereum/privacy pools