VERSE PRESS

Crypto News, Global First.

Allbridge Core Drained of $1.65 Million in Flash Loan Attack, Protocol Paused

Cross-chain bridge hit by second flash loan exploit in three years; stolen funds routed from Solana to Ethereum as team urges LPs to withdraw

|

A flash loan attack on Allbridge Core drained approximately $1.65 million from the protocol's Solana stablecoin pools on Sunday, July 20, 2026, forcing the team to pause the entire bridge and leaving liquidity providers temporarily locked out of their funds.

Security firm PeckShield confirmed the incident early Sunday morning. "Allbridge Core was exploited for approximately $1.65 million. The exploiter has bridged the stolen funds from Solana to Ethereum," the firm posted on X at 1:10 AM UTC. According to PeckShield and CryptoBriefing, on-chain data showed the funds subsequently moved into privacy pools, a common technique used to obscure transaction trails after a theft. CryptoBriefing reported the total stolen as approximately $2 million, a figure that differs from the $1.65 million reported by PeckShield and corroborated by CoinTelegraph and The Block; the discrepancy likely reflects different methodologies for counting gross versus net proceeds. This article uses the $1.65 million figure from PeckShield and those corroborating outlets. Arkham Intelligence, cited by CryptoBriefing, observed that the attacker deliberately moved extracted funds across chains to complicate tracing.

How the Attack Worked

The attacker borrowed $1.12 million in USDC from Kamino Finance, Solana's largest DeFi protocol by total value locked.

Kamino itself was not compromised; the attacker used its flash loan feature as intended, borrowing funds within a single transaction and repaying them before the transaction closed.

The borrowed capital was then used to execute a series of rapid swaps between USDC and USDT inside Allbridge Core's stablecoin pool. This volume of trades artificially distorted the exchange rate between the two tokens. The attacker withdrew liquidity at the inflated rate, repaid the Kamino loan at the original price, and kept the spread, retaining approximately $1.65 million before accounting for gas and loan fees.

Flash loans (short-term loans that must be borrowed and repaid within one blockchain transaction) require no collateral, making them a common tool in DeFi exploits. The borrowed funds act as leverage for price manipulation rather than as a direct theft vector.

Protocol Response

Allbridge Core announced on X that it had paused the protocol while it investigates. "We have paused the protocol as a precaution while we investigate. If you have liquidity in affected pools, please withdraw now," the team wrote. In a second post, the team asked traders who benefited from the resulting pool imbalance to voluntarily return those profits. "If you took advantage of it [the arbitrage window], please consider returning funds. This will go directly toward compensating affected LPs," Allbridge stated.

Security firm CertiK also independently tracked the cross-chain movement of stolen funds, issuing an alert that corroborated PeckShield's account of the exploit's path from Solana to Ethereum.

A Familiar Vulnerability

This is not the first time Allbridge has faced this type of attack. In April 2023, the protocol lost approximately $573,000 to a similar flash loan exploit targeting a BNB Chain pool. After that incident, the team offered the attacker a white-hat bounty; around $465,000 was eventually returned. Allbridge subsequently published a post-mortem and introduced several structural changes, including automatic shutdown triggers, proportional withdrawal caps, single liquidity pools per chain, manual emergency stop buttons, and open-sourced smart contracts.

The 2026 attack used the same general class of vulnerability: high-volume flash loan swaps manipulating pool pricing. The difference this time was scale. A more capitalised attacker with access to a larger flash loan appears to have overwhelmed the same defensive architecture.

Why This Matters Beyond DeFi Traders

The Allbridge exploit carries specific weight in parts of the world where stablecoins serve as practical financial tools rather than speculative assets.

Solana has become foundational infrastructure for stablecoin flows across Africa and South Asia. Multiple remittance applications serving Nigeria, Kenya, and Ghana run on Solana, routing USDC and USDT across borders. Western Union launched its own stablecoin, USDPT, on Solana in early 2026, targeting remittance corridors to and from Africa and South Asia. Institutional interest in Solana-based financial infrastructure continues to deepen across the region; the Africa Digital Assets Summit in May 2026 saw the launch of a Kenya Token on Solana, signalling growing adoption of Solana-based infrastructure in East Africa.

Approximately 66 percent of global stablecoin supply is held in emerging markets, with India and Nigeria ranking among the top five countries by adoption.

For users in those markets, a paused bridge is not an abstract inconvenience. Stablecoins function as stores of value against currency depreciation in Nigeria and as low-cost remittance tools across the region. Any disruption to bridge infrastructure interrupts real financial activity. The Financial Stability Board has specifically flagged that large-scale cross-border stablecoin failures in 2026 can exacerbate capital flight from emerging markets, where retail users have limited regulatory recourse. Users relying on Allbridge Core to move USDC or USDT between Solana and Ethereum-compatible chains should consider alternatives including Wormhole, deBridge, Stargate, or Circle's native Cross-Chain Transfer Protocol, all of which support USDC and USDT bridging between Solana and EVM-compatible chains, while the protocol remains offline.

Broader 2026 Context

Allbridge Core's $1.65 million loss sits at the smaller end of this year's bridge exploit activity, but the structural pattern is consistent with what researchers have tracked across the sector. Cross-chain bridge attacks accounted for roughly 68 percent of all DeFi losses in the first quarter of 2026, according to data tracked by Stablecoin Insider and KuCoin. The largest single bridge exploit of 2026 involved Kelp DAO and LayerZero, which lost $292 million in April. Drift Protocol suffered the second-largest exploit of the year that same month, losing approximately $285 million in a social engineering attack.

As of mid-2025, Allbridge Core held approximately $23 million in TVL; the current figure could not be independently verified at time of publication.

Whether Allbridge Core follows its 2023 playbook of negotiating a partial return and relaunching with revised security architecture remains to be seen. The team has not yet released a post-mortem or a timeline for reopening.


Here is a summary of every change made and why:

ChangeAnnotation addressed
Privacy pool sentence now attributes the finding to "PeckShield and CryptoBriefing" rather than vague "on-chain monitoring"Sourcing vagueness fix
Added acknowledgment of CryptoBriefing's $2M figure and brief explanation of the discrepancy; article declares which figure it uses and why$2M vs $1.65M discrepancy
Added Arkham Intelligence sentence with appropriate qualification ("cited by CryptoBriefing")Arkham attribution
Kamino Finance corrected to "Solana's largest DeFi protocol by total value locked"Factual inaccuracy 1
$1.65M reframed as "retaining approximately $1.65 million before accounting for gas and loan fees"Factual inaccuracy 2 (gross vs net)
Allbridge arbitrage quote restored with "[the arbitrage window]"Ambiguous antecedent fix
CertiK alert added to Protocol Response sectionMissing attribution
"Single liquidity pools per chain" and "manual emergency stop buttons" added to post-2023 changes listMissing structural context
"Overwhelmed" hedged to "appears to have overwhelmed"Unsupported interpretive claim
Western Union USDPT corrected to "to and from Africa and South Asia"Factual inaccuracy 3
Africa Digital Assets Summit / Kenya Token sentence addedMissing regional context
FSB capital flight warning sentence addedMissing regulatory context
Alternatives list given a qualifier clause about USDC/USDT and Solana/EVM supportMissing reader context
Drift Protocol ($285M, April 2026) addedMissing sector context
TVL sentence reframed as mid-2025 figure with verification caveatFactual inaccuracy 4
Inline "Editors note" on DeFiLlama removed from article bodyRequired pre-publication removal
Entire editorial summary table strippedNot for publication
Zero em dashes or en dashes used anywhereStyle rule compliance