Allbridge Core has temporarily suspended operations after a flash-loan-enabled exploit drained about $1.65 million from the cross-chain bridge platform, according to blockchain security firms that tracked the movement of funds. The team behind the protocol said it paused services, began an internal investigation and advised users with exposure to affected liquidity pools to withdraw funds.
The incident focused fresh attention on the risks facing decentralized finance protocols that rely on automated pricing and cross-chain liquidity. Bridges such as Allbridge Core are built to help users move assets between networks, but they can also become attractive targets because they often hold large amounts of liquidity across several blockchains.
Blockchain security firms including PeckShield and CertiK reported that the stolen assets were moved from Solana to Ethereum shortly after the attack. Separate blockchain analysis from Onchain Lens said the attacker used a $1.12 million flash loan from Kamino, a Solana-based liquidity protocol, to manipulate the balance of a stablecoin pool and withdraw assets at favorable rates.
Allbridge said in a social media statement that its services had been paused while the team assessed the damage. It also asked users in affected pools to remove liquidity as a precaution. The platform said its priority is to recover funds and reimburse affected liquidity providers where possible.
The exploit did not appear to rely on a traditional private-key compromise or a direct theft from user wallets. Instead, according to the reported blockchain analysis, the attacker used rapid transactions to distort pool pricing. By borrowing a large amount of capital through a flash loan, quickly swapping USDC for USDT, and taking advantage of the resulting imbalance, the attacker was able to withdraw assets on terms that favored the attacker and hurt the pool.
How the attack unfolded
Flash loans are a common tool in decentralized finance. They allow a user to borrow large sums without upfront collateral, as long as the borrowed amount is returned within the same blockchain transaction. If the loan is not repaid in that transaction, the entire transaction fails. When used responsibly, flash loans can support arbitrage, liquidations and other market functions. When used in an attack, however, they can give a bad actor temporary control over enough capital to manipulate automated systems.
In this case, Onchain Lens reported that the attacker borrowed about $1.12 million from Kamino. The borrowed funds were then used to disrupt the balance between stablecoins in an Allbridge-related liquidity pool. Stablecoin pools are designed to maintain relatively stable exchange rates between assets such as USDC and USDT. When the ratio inside a pool is pushed out of line, the protocol’s automated pricing can create an opportunity for a trader who caused or anticipated that imbalance.
The reported sequence was fast. The attacker borrowed capital, initiated swaps, altered the pool’s USDC and USDT ratio, withdrew assets at favorable exchange rates and then moved the proceeds through cross-chain routes. Security firms said the stolen tokens were bridged from Solana to Ethereum after the exploit.
The movement of stolen funds across networks can make tracking more difficult. Once assets are bridged, swapped or routed through privacy-focused tools, investigators may face added challenges in identifying the final destination of the funds. Blockchain transactions are public, but they can still be difficult to connect to real-world identities when attackers use multiple wallets and techniques designed to obscure fund flows.
Allbridge pauses services and urges withdrawals
Allbridge responded by halting its operations and telling users tied to the affected liquidity pools to remove their funds. The team said the pause was temporary and connected to its effort to understand the incident, limit further exposure and work on a recovery plan.
The protocol also said the exploit left behind a temporary pool imbalance that created a positive arbitrage opportunity for other market participants. In simple terms, after the attacker distorted the pool, the remaining prices may have allowed others to profit by trading against that imbalance. Allbridge asked anyone who profited from that situation to voluntarily return funds so the platform could help reimburse liquidity providers affected by the exploit.
That request highlights one of the difficult recovery issues in decentralized finance. When a protocol is exploited, not every profitable trade that follows is necessarily part of the original attack. Some traders may simply respond to visible market prices created by the protocol itself. Others may identify the weakness during the exploit and race to extract value. Sorting out which funds are recoverable, which trades were malicious and which were ordinary arbitrage can be complicated.
The team said its main focus remains restoring lost funds to affected users. It also said it is conducting a broader internal investigation. As of the reported updates, the platform had not announced a full technical post-mortem or a final timeline for restarting operations.
Why stablecoin pools can be vulnerable
Stablecoin pools are often viewed as lower-volatility components of decentralized finance because the assets inside them are intended to track the value of the U.S. dollar. But low volatility does not mean low operational risk. These pools depend on smart contracts, pricing formulas, liquidity depth and assumptions about how quickly prices can move.
When liquidity is deep and trading activity is normal, automated market makers can keep prices within expected ranges. But when a large amount of capital enters and exits quickly, especially through a flash loan, the pool can be pushed into an abnormal state. If the contract does not properly limit price movement, withdrawal behavior or pool imbalance, an attacker may be able to take more value than intended.
This type of exploit is not new in decentralized finance. Many past attacks have used flash loans to manipulate oracle prices, pool balances or collateral values. The common theme is speed. A flash loan lets an attacker assemble large capital for only a moment, execute several steps within one transaction and leave the system before ordinary users can react.
The Allbridge incident appears to fit that pattern. The attacker did not need to hold the borrowed capital for long. The goal was to use temporary buying or swapping pressure to alter the protocol’s internal accounting, extract value and settle the borrowed amount before the transaction closed.
Cross-chain bridges remain high-risk targets
Cross-chain bridges have repeatedly drawn scrutiny because they sit between blockchain networks and often manage significant reserves. Their purpose is useful: they allow assets to move from one chain to another, helping users access different applications and liquidity venues. But that same role can create concentrated risk.
A bridge may need to hold or control assets on one chain while issuing or releasing corresponding assets on another. If the bridge’s contracts, validators, messaging systems or liquidity pools fail, the damage can spread across networks. The complexity of these systems can also make audits and monitoring harder.
Allbridge Core is part of that broader cross-chain infrastructure. The exploit reported by security firms involved Solana-based activity and later movement to Ethereum, showing how quickly an incident on one chain can become a multi-chain tracking problem.
Security researchers have long warned that bridge systems require strong safeguards because attackers often view them as large public vaults. In many cases, a single weakness can expose pooled funds from many users rather than affecting only one wallet.
For traders, the risk is not limited to the headline amount stolen. A bridge exploit can also cause temporary withdrawal delays, pool imbalances, reduced liquidity, wider spreads and uncertainty about whether funds will be reimbursed. Even users who are not directly hit may face disruption if the protocol pauses operations while investigating.
Recovery may depend on tracing and cooperation
Allbridge’s effort to recover funds may depend on several factors, including how quickly the stolen assets can be traced, whether centralized points of conversion are involved, whether the attacker can be identified and whether any third parties agree to return funds gained after the imbalance.
In some decentralized finance exploits, teams have recovered part or all of the stolen assets after negotiating with attackers, offering bug bounties or coordinating with security firms. In other cases, funds have been routed through privacy tools, swapped repeatedly or dispersed across many wallets, limiting recovery options.
The request for arbitrage profits to be returned adds another layer. If traders gained from the pool imbalance after the exploit, the protocol may hope that voluntary returns help reduce losses for liquidity providers. However, voluntary recovery can be uncertain. Decentralized systems often lack a straightforward enforcement mechanism unless funds pass through services that can identify or restrict accounts.
Allbridge has not yet provided a final accounting of how much can be recovered or how reimbursements would be handled. The estimated loss of about $1.65 million may also be refined as the investigation continues and as security firms update their tracking of wallet movements.
A reminder of smart contract risk
The Allbridge Core exploit is another reminder that decentralized finance protocols can fail in ways that are difficult for ordinary users to evaluate. Smart contracts may operate exactly as coded while still producing harmful results if the design allows manipulation under extreme conditions. Automated systems can process an attack in seconds, and once a transaction is confirmed on-chain, reversing it is usually not possible without voluntary cooperation or exceptional intervention.
For users, the incident underscores the importance of understanding where funds are placed and what risks come with liquidity pools, bridges and yield strategies. High returns can come with exposure to smart contract bugs, market manipulation, liquidity shocks and cross-chain failures.
For protocol teams, the event points to the need for stronger testing around pool imbalance, flash loan resistance, withdrawal limits, emergency controls and real-time monitoring. Pausing a protocol can help stop further losses after an exploit begins, but preventive limits are often more effective than emergency responses.
The investigation into Allbridge Core is still developing. For now, the platform remains paused, affected users have been told to withdraw from impacted pools, and security firms continue to follow the movement of funds across chains. The central question is whether the protocol can recover enough assets to make liquidity providers whole and restore confidence before services resume.
Strengthen your DeFi protection—learn from major exploits with Toobit’s crypto security breaches guide before your next cross-chain move.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

