Allbridge Core said an attacker exploited the swap logic in its Solana liquidity pools over the weekend, draining roughly $1.66 million in crypto from the cross-chain stablecoin bridge. The project said the incident affected pool-based swaps and did not compromise user wallets, private keys, or bridge routes that do not depend on liquidity pools.

How the exploit unfolded

According to Allbridge’s post-mortem, the attacker began by taking out a flash loan and using it against the protocol’s Solana-based pools. The hacker borrowed about $1.12 million in USDC from a lending protocol and swapped that amount into USDT.

From there, the attacker carried out five “same-asset swaps,” repeatedly exchanging 100,000 USDT for decreasing amounts of the same token. Allbridge said its swap path handled a trade where the input and output asset were the same in the same way it would treat any normal token pair.

That design, the project said, caused the two sides of the trade to reference the same pool while their accounting drifted apart. With each iteration, the pool’s internal pricing moved further away from actual market value.

Price distortion and drained funds

After pushing the pool’s internal USDT pricing far out of line, the attacker was able to exchange just 4,000 USDT for 2.24 million USDC, according to Allbridge. The hacker then repaid the flash loan and kept the remaining assets.

Allbridge said the attacker’s net gain was 1,118,239 USDC and 538,692 USDT, for a total of about $1.66 million. The project also said a safeguard intended to limit liquidity pool imbalance had been set too permissively, allowing the mispricing to grow to profitable levels before the protection activated.

Operational response

Following the exploit, Allbridge said it restored routes that do not rely on liquidity pools. At the same time, the protocol said it plans to discontinue pool-based swaps altogether.

The team added that it has traced $1.63 million of the stolen funds. According to the project, those assets were bridged from Solana to a single consolidation address on Ethereum before being dispersed in several directions.

What was and was not affected

Allbridge said the incident was limited to the affected liquidity pool mechanism on Solana. It stated that no user wallets were breached, no private keys were exposed, and no non-pool bridge routes were impacted.

The exploit highlights the risks in swap accounting and liquidity pool protections for cross-chain infrastructure, particularly when internal pricing can be pushed away from market reality before safeguards intervene. In this case, Allbridge has attributed the loss to a flash-loan-assisted manipulation of pool swap logic rather than a compromise of user accounts or core wallet security.

Source: dailyhodl.com