Allbridge Core Exploit:
$1.65M Lost to Solana Pool Manipulation
$1.65 million was reportedly lost from Allbridge Core after a flash loan distorted its Solana USDC/USDT pool; proceeds were bridged to Ethereum.

- Incident Date: July 19, 2026
- Target: Allbridge Core
- Target Overview: Allbridge Core is a cross-chain stablecoin bridge that uses liquidity pools on supported networks to facilitate transfers. The reported exploit targeted its USDC/USDT liquidity on Solana.
- Total Loss: Approximately $1,650,000, according to PeckShield and CertiK; Onchain Lens separately traced more than $1,100,000 in extracted value, and Allbridge has not yet published a reconciled total
- Reported Solana Attacker Address:
FhffBraZsGn4H2LxLNToEcaHWEfWwT2UcSz4oRHb7Qdc - Primary Exploit Transaction:
3LNLaGi36bqoSBFBqcQ3ZvDbnGCxrxu4rqahZrnfHZjKSYxfR1mqiCXtBXjjeBmoRQDeSiKxZ7c1nFb8pBgTY39Q - Ethereum Recipient Address:
0x651591b68A9c9650FB23F642162353306281ffDe - Attack Vector: Flash loan attack (liquidity pool price manipulation)
Incident Review & Technical Details
1. Attack Path
- The attacker sourced temporary capital from Kamino: According to Onchain Lens, the attacker borrowed approximately $1.12 million in USDC through a Kamino flash loan. This provided enough atomic liquidity to move the balance of Allbridge Core's Solana stablecoin pool without committing comparable capital of the attacker's own.
- Rapid swaps distorted the pool ratio: The attacker repeatedly swapped USDC for USDT, pushing the pool's internal asset ratio away from the external one-to-one value of the two stablecoins. No reviewed source has identified a compromised private key or forged cross-chain message; the reported attack instead exploited the economic behavior of an imbalanced liquidity pool.
- Value was withdrawn at the manipulated rate: With the pool in an artificial state, the attacker withdrew liquidity at the distorted exchange rate and repaid the flash loan within the same transaction. Onchain Lens estimated that the sequence extracted more than $1.1 million and identified approximately $2.24 million in USDC as the largest single Allbridge withdrawal; the latter is a gross withdrawal figure, not the attacker's net profit.
- Proceeds moved from Solana to Ethereum: PeckShield reported that the stolen funds were bridged from Solana to Ethereum. CertiK identified
0x6515...ffDeas the Ethereum recipient before further dispersion, while Onchain Lens reported that proceeds subsequently moved through privacy infrastructure. The reviewed alerts did not name the specific privacy protocol or publish a complete laundering trace.
2. Impact Scope
- Protocol-Level Loss: PeckShield and CertiK estimated the loss at approximately $1.65 million. Onchain Lens reported more than $1.1 million in extracted value, so the final loss, recoveries, and attacker net profit remain subject to Allbridge's reconciliation.
- Liquidity-Provider Exposure: Allbridge told liquidity providers in affected pools to withdraw immediately. The team also asked traders who profited from the temporary post-attack arbitrage window to return those gains for compensation of affected liquidity providers.
- Protocol Availability: Allbridge Core paused the protocol as a precaution while it investigated the incident. The team did not identify every affected pool or provide a reopening timetable in the reviewed statements.
- Ecosystem Contagion: No reviewed source reported a compromise of Solana, Ethereum, Kamino, USDC, or USDT, and no stablecoin depeg or loss at an integrated third-party protocol was attributed to this incident.
3. Official Statements
- Allbridge: The project confirmed a security incident, paused Allbridge Core, and urged liquidity providers in affected pools to withdraw. It published
0x01a4...A4D0for the voluntary return of profits from the temporary arbitrage window, saying returned funds would go toward compensating affected liquidity providers. - Allbridge on recovery: In a follow-up response, the team said its goal was to return all affected funds and directed users to its official channels for updates. It did not announce a finalized compensation schedule.
4. Investigation Progress
As of July 20, 2026, Allbridge had not published a technical post-mortem, a final affected-pool inventory, or a reconciled loss figure. The public evidence supports a flash-loan-funded manipulation of Solana USDC/USDT pool ratios, but it does not yet establish which invariant, pricing formula, withdrawal check, or circuit breaker was insufficient.
The attacker-controlled Solana address was identified as Fhff...7Qdc, and CertiK linked the primary transaction 3LNLa...Y39Q to the incident. CertiK and PeckShield traced proceeds to Ethereum, with CertiK identifying 0x6515...ffDe before further dispersion. No reviewed source reported a confirmed freeze, negotiated return, or recovery of the stolen proceeds.
AUTOSEC.DEV Solution
Preventing a repeat of this attack requires validating both the pool's code-level invariants and its behavior under atomic, adversarial liquidity shocks.
- Secure Code Review - Allbridge Core's Solana pool reportedly allowed a $1.12 million USDC flash loan and rapid USDC/USDT swaps to create a withdrawal rate that produced more value than the attacker returned. AUTOSEC.DEV reviews stable-swap math, imbalance fees, deposit and withdrawal accounting, rounding behavior, and minimum-liquidity assumptions with invariant fuzzing designed to prove that no atomic sequence can extract unearned value.
- Red Team Assessment - The attack chained Kamino liquidity, repeated stablecoin swaps, a manipulated Allbridge withdrawal, and cross-chain dispersal into one operational workflow. AUTOSEC.DEV reproduces comparable flash-loan scenarios on a fork, tests rate-deviation and pool-imbalance circuit breakers, and measures whether pause controls, withdrawal limits, and monitoring can contain a drain before liquidity providers absorb the loss.