Cross-chain bridge Allbridge Core suffered a flash loan exploit resulting in an estimated $1.65 million loss, prompting an immediate protocol pause as multiple blockchain security firms flagged the incident. The attacker borrowed $1.12 million via a flash loan from Solana-based liquidity protocol Kamino, then manipulated the USDC/USDT stablecoin pool ratios to withdraw funds at favorable rates. The stolen assets were routed through privacy protocols to obscure the trail, and both PeckShield and CertiK reported that the attacker subsequently bridged the loot from Solana to Ethereum.
Allbridge confirmed the pause on X and urged users to withdraw liquidity from affected pools. The team noted the pool imbalance had created a temporary arbitrage window and offered an address for anyone who profited from it to return funds, stating the goal is to “return all affected funds” to liquidity providers. No reimbursement plan or restart timeline has been disclosed; the team is treating the exploit as an active security incident. The incident reinforces recurring risks in DeFi, where permissionless flash loans can be weaponized against protocol logic. Allbridge Core’s pause is a containment measure, and the community awaits further disclosure on impact assessment and recovery steps.