Allbridge Core has suspended its cross-chain stablecoin protocol after a security exploit resulted in the loss of approximately $1.65 million, prompting the team to launch an investigation and urge liquidity providers to withdraw funds from affected pools.
The incident targeted Allbridge Core’s Solana deployment, where blockchain security researchers identified an attack that manipulated the protocol’s stablecoin liquidity pools. Shortly after the exploit, on-chain analysts reported that the stolen assets were bridged from Solana to Ethereum, a move that could make recovery efforts more difficult.
Attack Exploited Stablecoin Pool
According to blockchain investigators, the attacker initiated the exploit by securing a flash loan of roughly $1.12 million in USDC through the Solana-based lending protocol Kamino. The borrowed funds were then used to execute a series of rapid USDC and USDT swaps that distorted the exchange rate within Allbridge Core’s stablecoin pool.
The manipulated pricing allowed the attacker to withdraw assets at favorable rates before repaying the flash loan within the same transaction. Security firms estimated the total losses at approximately $1.65 million.
Following the exploit, the Allbridge team immediately paused the protocol and began assessing the full scope of the incident.
Protocol Response and User Guidance
As a precaution, Allbridge advised liquidity providers to remove funds from affected pools while the investigation continues. The team also acknowledged that the exploit temporarily created an arbitrage opportunity due to the resulting pool imbalance.
In its public update, the protocol encouraged anyone who benefited from the temporary pricing imbalance to voluntarily return the proceeds, stating that recovered funds would be directed toward compensating affected liquidity providers. The developers added that restoring user funds remains their primary objective.
Growing Security Concerns
The latest exploit adds to an ongoing series of attacks targeting decentralized finance infrastructure, particularly cross-chain bridge protocols that manage significant pools of digital assets. These platforms continue to attract attackers because they facilitate the movement of assets across multiple blockchain networks.
The investigation remains ongoing, and Allbridge has not announced when normal operations will resume. The team is expected to release additional technical findings once the incident review is complete.