Allbridge Core Suspends Service Following $1.65M Flash Loan Attack on Solana
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- Allbridge has suspended its core services after exploiters stole $1.65 million from the platform.
- The attackers capitalized on a $1.12 million flash loan from Kamino to launch the attack.
- The DeFi platform urged users to withdraw their assets, while it continues to investigate the incident
Cross-chain stablecoin bridge Allbridge has temporarily halted its Allbridge Core services after a security attack affected its Solana pools. In an X post on Monday, blockchain security firm PeckShieldAlert reported that the attacker stole roughly $1.65 million through a flash loan attack, targeting the Solana (SOL) network. The stolen funds were moved from the Solana network to Ethereum via a bridge, making them very difficult to track or recover.
#PeckShieldAlert @Allbridge_io Core was exploited for ~$1.65M.
The exploiter has bridged the stolen funds from #Solana to #Ethereum pic.twitter.com/ZOZysmJcAH
— PeckShieldAlert (@PeckShieldAlert) July 20, 2026
Details of the Flash Loan Exploit that Forced Allbridge Core to Halt Operations
Onchain Lens, another blockchain firm, reported that the attacker did not use their money to launch the attack. Instead, the exploiter first received a $1.12 million USDC flash loan from Kamino. For context, a flash loan is a type of loan that must be borrowed and repaid within the same blockchain transaction. If the loan recipient fails to repay the loan immediately, the whole transaction is canceled.
The borrowed funds allowed the attacker to repeatedly swap USDC and USDT inside Allbridge Core’s stablecoin pool. These trades changed the pool’s balance and created a false exchange rate between the two assets. After successfully changing the exchange rate, the exploiter advanced to withdrawing liquidity from the pool using those incorrect prices.
Reports showed that the largest withdrawal during the exploit was roughly $2.24 million. The attacker repaid the $1.12 million flash loan to Kamino in the same transaction and kept the remaining amount as profit. Notably, the entire process happened in a single block, making it very difficult for Allbridge’s security team to stop it.
🚨 Allbridge Core on Solana just got drained in a single transaction
No leaked key
No bridge exploitThe attacker didn't spend a dollar of their own money to do it
Here's what actually happened:
Step one: flash-borrow ~$1.12M USDC from @KaminoFinance
No collateral, no risk,…
— DBCrypto (@DBCrypt0) July 20, 2026
Allbridge Security Team Breaks Silence, Urges Users to Withdraw Assets
The Allbridge security team has confirmed the exploit via an X post on the platform’s official handle. According to the tweet, the team has halted the protocol’s operations. In addition, the team has opened investigations into the incident. Users were also advised to withdraw their assets from the platform as soon as possible.
The Allbridge security team added:
“The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage of it, please consider returning funds to the address below – this will go directly toward compensating affected LPs.”
Allbridge Core is experiencing a security incident.
We have paused the protocol as a precaution while we investigate.If you have liquidity in affected pools, please withdraw now.
The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage… pic.twitter.com/Ovg7yT35SM
— Allbridge (@Allbridge_io) July 19, 2026
DeFi Protocol’s Pricing System Remains a Source of Concern Amid Rising Hack Incidents
The main enabler of the exploit on Allbridge Core was that the pool relied on its own token balances to calculate prices. Because these balances could be changed with borrowed money, the attacker was able to create false prices and use them to withdraw more assets than they should have received.
The attack was not based on stolen private keys or a weakness in the bridge itself. Instead, it used a price manipulation method that has appeared in several decentralized finance attacks over the past few years. Overall, price manipulation scams will remain a major concern, as attackers have often exploited vulnerabilities in pricing systems to steal large sums from Decentralized Finance (DeFi) platforms.
Meanwhile, DeFi platforms have faced increased attacks over the past few weeks, as exploiters continue to exploit their vulnerabilities. On July 16, Crypto2Community reported that Ostium, a decentralized perpetual trading platform, was the target of a security breach, resulting in the loss of about $21 million. Summer.fi, another DeFi platform, also lost $6 million earlier this month. The Summer. fi attacker manipulated the platform’s liquidity via a $65.4 million flash loan.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







