Incident Summary
Published 7/20/2026, 6:17:44 PM
On July 19–20, 2026, Allbridge Core’s Solana-based liquidity pools were exploited for approximately $1.65 million through a sophisticated flash loan attack. The attacker manipulated the protocol's internal pricing state within a single transaction to withdraw liquidity at distorted rates, bypassing existing security measures.
Incident Summary
The exploit targeted native stablecoin pools (USDC/USDT) on the Solana network. Security firms CertiK and PeckShield confirmed the total loss at approximately $1.65 million.
| Metric | Value | Source |
|---|---|---|
| Total Loss | ~$1.65 million | [Verified: CertiK/PeckShield] |
| Flash Loan Amount | $1.12 million USDC | [Source: https://www.coindesk.com] |
| Flash Loan Source | Kamino (Solana Lending Protocol) | [Source: https://www.kucoin.com] |
| Target Network | Solana | [Source: https://www.tradingview.com] |
| Status | Protocol Paused | [Source: https://finance.yahoo.com] |
Technical Mechanics of the Attack
The attack was executed in a single, atomic transaction on the Solana blockchain, following these steps:
- Flash Loan Acquisition: The attacker borrowed $1.12 million USDC from Kamino, a prominent Solana lending protocol [Source: https://www.lcx.com].
- Pool Manipulation: Using the borrowed funds, the attacker performed high-volume swaps between USDC and USDT within the Allbridge Core pools. These swaps were designed to drastically shift the ratio of assets in the pool.
- Value Extraction: By distorting the internal pool state, the attacker was able to withdraw liquidity at a "manipulated" favorable rate that did not reflect the true market value of the assets.
- Repayment and Exfiltration: The original $1.12 million loan was repaid to Kamino within the same transaction. The remaining profit (~$1.65 million) was bridged from Solana to Ethereum and routed through privacy protocols to obscure the trail.
Reported Solana Transaction ID: 3LNLaGi36bqoSBFBqcQ3ZvDbnGCxrxu4rqahZrnfHZjKSYxfR1mqiCXtBXjjeBmoRQDeSiKxZ7c1nFb8pBgTY39Q [Note: not independently confirmed].
Root Cause and Vulnerability
The exploit targeted a fundamental flaw in Allbridge Core's cross-chain bridge architecture:
- Pricing Vulnerability: The protocol's pricing and internal state were calculated based on the immediate pool ratio. This ratio could be moved significantly by a single large transaction (a flash loan), creating a temporary price discrepancy [Note: not independently confirmed].
- Lack of TWAP: The absence of a Time-Weighted Average Price (TWAP) mechanism or multi-block safeguards allowed the attacker to exploit this discrepancy before the protocol could adjust to the true market price [Note: not independently confirmed].
- Bypassed Defenses: Following a similar exploit in April 2023 on the BNB Chain, Allbridge had implemented a Rebalancer Authority and automatic shutdown for extreme imbalances. However, because the entire manipulation occurred within one transaction, these safeguards were reportedly circumvented before they could trigger [Note: not independently confirmed].
Current Status
Allbridge Core has paused its operations to investigate the breach. The protocol has reportedly provided a return address for the attacker (0x01a494079DCB715f622340301463cE50cd69A4D0) in hopes of negotiating a recovery, similar to the partial recovery achieved after their 2023 incident [Note: return address and 2023 recovery details not independently confirmed].