Allbridge Pauses After $1.65M Flash Loan Attack Drains Solana
In brief
- Flash loan attack: attacker borrowed $1.12M from Kamino to manipulate Allbridge's stablecoin pools
- Rapid swaps distorted internal pricing, creating $2.24M USDC arbitrage opportunity
- Protocol paused; team confirms user liquidity safe, plans relaunch without pools
Attack mechanics
The attacker borrowed $1.12 million through a flash loan from Kamino, a Solana lending protocol. Using that capital, the attacker ran a rapid series of stablecoin swaps to distort the internal accounting that prices assets in Allbridge's pools. The resulting imbalance created a window where mispriced assets could be arbitraged.
The attacker then swapped a few thousand dollars of USDT for approximately $2.24 million in USDC before bridging the proceeds to an Ethereum address. This represents a net extraction of roughly $1.65 million from the protocol's Solana pools.
Allbridge's architecture made it vulnerable to this type of attack. The protocol's Core product uses pools of native stablecoins such as USDC and USDT rather than minting wrapped tokens. This design choice exposed the bridge to pricing manipulation when an attacker could borrow enough capital to move the pools significantly out of balance.
Response and history
The Allbridge team stated there is no threat to users' liquidity and is working to relaunch Core without liquidity pools. The pause came as a precaution while the team investigates the incident.
This isn't Allbridge's first brush with flash loan exploits. In April 2023, a similar flash-loan attack drained around $573,000 from its BNB Chain pools. Despite raising $2 million in 2022 to expand the bridge and fund security audits, the protocol has been hit twice by the same class of vulnerability.
The attack underscores broader risk in the DeFi ecosystem. More than $840 million was lost to DeFi hacks in just the first five months of 2026. Recent examples include a bridge between Axelar and Secret Network that was drained of $4.67 million after attackers exploited an "infinite mint" bug in a custom token contract.


