Allbridge Core Cross-Chain Bridge Exploited for $1.65 Million via Flash Loan Attack

The attacker used a Kamino USDC flash loan of about $1.12 million to distort Allbridge Core’s stablecoin pool through rapid USDC/USDT swaps, withdrew funds at manipulated rates, repaid the loan, and kept the arbitrage profit.
This incident is at least the sixth cross-chain bridge attack since May, underscoring the ongoing vulnerability of DeFi cross-chain infrastructure.
Allbridge previously suffered a flash loan attack in April 2023 on its BNB Chain pool, with about $573,000 drained; approximately $465,000 was recovered through a white-hat arrangement.
Allbridge expanded its cross-chain capabilities by integrating with Algorand in January 2026, broadening its coverage beyond Ethereum-compatible networks.
Cross-chain bridge Allbridge Core was exploited for approximately $1.65 million, forcing the protocol to suspend operations while its team investigated the attack, according to The Block and LCX. The attacker used a flash loan — a type of uncollateralized loan that must be repaid in the same transaction — to manipulate stablecoin prices and pocket the difference.
The Allbridge team paused the bridge as a precaution and urged affected liquidity providers to withdraw their funds. The exploit added to a growing list of cross-chain bridge attacks, marking at least the sixth such incident since May.
The attacker borrowed roughly $1.12 million in USDC from Kamino, a Solana-based lending protocol, according to The Block. They used that loan to flood Allbridge Core's stablecoin pool with rapid USDC and USDT swaps. This pushed the pool's prices out of balance.
Once prices were distorted, the attacker withdrew funds at the manipulated rates — getting far more than fair value. They then repaid the flash loan and kept the arbitrage profit. The stolen funds were bridged from Solana to Ethereum and moved into privacy pools to hide their trail, per LCX.
After the exploit, the Allbridge team paused the entire protocol. They warned that pool imbalances had created a temporary arbitrage window — meaning other users could also lose money if they left funds in the pools, according to LCX and Erit V News.
The team urged all liquidity providers to withdraw immediately. Allbridge has not yet released a full post-mortem or confirmed whether any recovery is possible. The protocol's cross-chain bridge — which connects networks like Solana and Ethereum — remained offline as of the latest reports.
This is not Allbridge's first flash loan attack. In April 2023, attackers drained about $573,000 from an Allbridge pool on BNB Chain using a similar method. Of that amount, roughly $465,000 was recovered through a white-hat arrangement — where an ethical hacker returns stolen funds, often in exchange for a bounty.
Allbridge has been expanding its reach despite past security issues. In January 2026, the protocol integrated with Algorand, broadening its network beyond Ethereum-compatible chains, according to LCX. That expansion now raises questions about how security scales alongside new integrations.
This exploit is at least the sixth cross-chain bridge attack since May, according to The Block. Bridges are popular targets because they hold large pools of assets from multiple blockchains in one place. A single flaw in price logic or pool management can open the door to massive losses.
Flash loan attacks are especially hard to prevent. They happen in a single transaction — often in seconds — giving teams almost no time to react. The Allbridge incident shows that even protocols with prior attack experience remain exposed, and that stronger safeguards and faster on-chain monitoring are urgently needed across the DeFi space.
Publishers
31
Articles
33
Reach
64