Allbridge Core has paused its protocol after a security incident that reportedly drained about $1.65 million from its Solana deployment on Sunday. The cross-chain stablecoin bridge said it halted operations as a precaution while it investigates the breach.
Protocol pause after incident
In a post on X, Allbridge Core said it was “experiencing a security incident” and had paused the protocol while looking into what happened. The team also urged users with liquidity in affected pools to withdraw it.
The reported exploit hit Allbridge Core’s Solana side. By the time the incident was flagged publicly, the attacker had already moved the stolen funds off Solana, bridged them to Ethereum and then sent them into privacy pools.
How the attack reportedly worked
Blockchain analytics account Onchain Lens said the exploit began with a $1.12 million USDC flash loan taken from Kamino. According to that account, the attacker then carried out rapid USDC and USDT swaps that distorted the exchange rate in Allbridge Core’s stablecoin pool.
After changing pool pricing, the attacker allegedly withdrew liquidity at manipulated rates, repaid the $1.12 million USDC flash loan and kept the remaining funds as profit. Based on the reported figures, the total amount drained was around $1.65 million.
Allbridge Core later said the manipulation left the pool imbalanced and briefly created a favorable arbitrage opportunity. The project called on anyone who benefited from that temporary pricing distortion to consider returning funds, saying any recovered amount would go toward compensating affected liquidity providers.
Cross-chain bridges remain a target
The incident adds to a growing list of attacks on bridge infrastructure. According to the report, this was at least the sixth attack aimed at a cross-chain bridge since May.
Bridges have repeatedly drawn attackers because they typically hold large asset pools that support representations of tokens across different blockchains. That structure can make pricing logic, liquidity pools and collateral stores especially sensitive to manipulation or other technical failures.
What is known so far
At the time of the report, Allbridge Core had not published a full technical breakdown of the exploit. What was publicly available pointed to a Solana-based pool manipulation, a flash-loan-assisted sequence of swaps, and a quick movement of funds from Solana to Ethereum before they were routed into privacy tools.
The protocol’s pause suggests the team is trying to contain further damage while assessing affected pools and potential losses for liquidity providers. The company’s public statements framed the $1.65 million figure and the exploit mechanics as part of an ongoing investigation rather than a finalized account.
The case highlights a familiar pattern in bridge-related incidents: attackers exploit a weakness in pool or pricing mechanics, extract value quickly, and move funds across chains before response measures can catch up. In this case, the immediate result was a precautionary shutdown and a request for affected users to withdraw liquidity while the investigation continues.
Source: cointelegraph.com