Allbridge Core Exploit Drains $1.65M as Solana Flash Loan Attack Targets Bridge Liquidity

Allbridge Core, a cross-chain stablecoin bridge, has suffered a major security breach after an attacker exploited its Solana liquidity pools in a flash loan attack, draining approximately $1.65 million in digital assets. The incident has forced the protocol to temporarily pause operations while security teams investigate the exploit and track the movement of stolen funds.
According to blockchain security researchers, the attacker manipulated liquidity pool balances using a large flash loan on Solana before converting the stolen assets and transferring them across networks. The stolen funds were later bridged from Solana to Ethereum, increasing concerns about vulnerabilities in cross-chain infrastructure.
The latest exploit highlights the continuing security challenges facing decentralized finance (DeFi) protocols, particularly bridges that manage liquidity across multiple blockchain ecosystems.
Allbridge Core Exploit: How the $1.65M Attack Happened
Allbridge Core operates as a cross-chain stablecoin transfer platform designed to enable native asset movement between different blockchain networks. Unlike traditional wrapped-token bridges, the protocol focuses on liquidity-based transfers between supported chains.
Initial investigations indicate that the attacker used a Solana-based flash loan to manipulate liquidity conditions inside Allbridge Core pools. Blockchain analysis platform Onchain Lens reported that the exploiter borrowed approximately $1.12 million through Kamino, a Solana decentralized finance protocol, before executing a series of transactions designed to distort pool ratios.
The attacker reportedly swapped large amounts of stablecoins, including USDC and USDT, creating an imbalance within the liquidity pool. By exploiting the temporary pricing difference, the attacker was able to withdraw assets at a favorable exchange rate and capture the resulting value difference.
Flash loan attacks are particularly dangerous because they allow users to borrow large amounts of capital without collateral, provided that the entire transaction is completed within a single blockchain transaction. Attackers often use this mechanism to manipulate prices, liquidity ratios, or smart contract calculations.
Security Firms Detect the Attack
Blockchain security companies quickly identified unusual activity involving Allbridge Core. PeckShield and CertiK flagged the exploit and tracked the movement of funds following the attack.
Security analysts observed that the attacker moved the stolen assets from Solana to Ethereum after draining the affected pools. Cross-chain transfers are often used by attackers to complicate recovery efforts because assets become distributed across different networks and wallets.
Following the breach, Allbridge Core confirmed that it had paused the protocol and advised liquidity providers to withdraw funds from affected pools while investigations continued. The team also warned that the exploit created temporary arbitrage opportunities because of the imbalance caused by the attack.
Allbridge Responds After the Security Breach
The Allbridge team has begun reviewing transaction data and working with blockchain security experts to understand the exact vulnerability exploited by the attacker. The protocol’s immediate response focused on limiting further losses and protecting remaining liquidity.
The incident represents another challenge for cross-chain bridges, which have become one of the most targeted sectors in decentralized finance. These protocols handle large volumes of assets and often maintain complex smart contract systems that connect multiple blockchain networks.
Allbridge Core promotes itself as a native stablecoin bridge supporting transfers between EVM and non-EVM blockchains. The platform provides liquidity pools that allow users to move stablecoins without relying on traditional wrapped assets.
However, the same liquidity-based architecture that improves efficiency can also create attack surfaces when pool pricing mechanisms or smart contract assumptions are manipulated.
Growing Security Risks Across DeFi Bridges
The Allbridge Core exploit adds to a growing list of DeFi security incidents affecting blockchain bridges. These platforms remain attractive targets because they often control significant liquidity while connecting separate blockchain ecosystems.
Security researchers have repeatedly warned that bridge protocols require stronger monitoring systems, improved auditing practices, and more advanced protection against economic attacks.
Flash loan exploits have become a common attack method because they allow attackers to execute complex financial strategies without needing significant upfront capital. Instead of breaking blockchain consensus, these attacks typically exploit weaknesses in smart contract logic, pricing formulas, or liquidity management systems.
The latest breach also reflects broader concerns around Solana-based DeFi applications. While Solana has experienced rapid ecosystem growth, projects built on the network continue to face security challenges related to smart contract design and liquidity management.
Impact on Users and Liquidity Providers
For Allbridge Core users, the attack raises concerns about the safety of funds deposited into cross-chain liquidity pools. Liquidity providers are typically exposed to smart contract risks because their assets remain locked within protocol-controlled contracts.
The team’s decision to pause the protocol aims to prevent additional losses while developers assess the damage. However, the long-term impact will depend on whether affected users can recover funds and whether the protocol introduces additional security measures.
Past DeFi incidents show that recovery efforts can involve negotiations with attackers, blockchain tracking, law enforcement cooperation, or community-led recovery programs. The outcome of the Allbridge Core investigation will determine the next steps for affected participants.
Why Cross-Chain Bridges Remain High-Risk Targets
Cross-chain bridges have historically accounted for some of the largest losses in crypto security history. Their complexity makes them difficult to secure because they must coordinate transactions between independent blockchain networks.
Unlike single-chain applications, bridges manage multiple systems, validators, liquidity pools, and smart contract interactions simultaneously. Any weakness in these components can create opportunities for attackers.
The Allbridge Core incident demonstrates that even established infrastructure providers must continuously improve security standards. Regular audits, real-time monitoring, automated threat detection, and stronger liquidity controls are becoming essential for protecting decentralized financial systems.
Conclusion
The Allbridge Core $1.65 million hack highlights the ongoing security risks facing the DeFi industry, especially cross-chain bridges that manage large pools of digital assets. The attacker’s use of a Solana flash loan to manipulate liquidity conditions demonstrates how sophisticated economic attacks continue to evolve.
Allbridge Core has paused operations and is working with security experts to investigate the exploit and track the stolen funds. While blockchain transparency allows investigators to follow transactions, recovering assets remains a complex challenge.
The incident serves as another reminder that blockchain innovation must be matched with stronger security frameworks. As cross-chain adoption expands, protocols will need improved safeguards to protect users and maintain confidence in decentralized finance infrastructure.