Cross-chain bridge protocol Allbridge Core has suffered a major security breach after an attacker drained approximately $1.65 million from its Solana deployment, forcing the platform to pause operations while security teams investigate the incident. Blockchain analysts reported that the exploit involved a flash loan-based manipulation attack, with the stolen assets later moved from Solana to Ethereum in an attempt to obscure the transaction trail.
The incident highlights renewed concerns around decentralized finance (DeFi) security, particularly for cross-chain bridges that manage liquidity across multiple blockchain networks. Allbridge Core has urged liquidity providers to withdraw funds from affected pools as investigators continue tracking the attacker’s movements.
Allbridge Core Suffers $1.65 Million Solana Exploit
Allbridge Core, a cross-chain stablecoin bridge designed to facilitate transfers between blockchain networks, became the target of a sophisticated exploit affecting its Solana-based infrastructure. According to blockchain security firms, the attacker extracted around $1.65 million in digital assets before moving the funds across networks.
The attack forced Allbridge to temporarily halt its protocol as a precautionary measure. The team confirmed that it was investigating the security incident and advised liquidity providers connected to affected pools to remove their funds until further updates were available.
Security researchers identified the attack as a flash loan manipulation strategy. The attacker reportedly borrowed approximately $1.12 million in USDC through Solana-based lending platform Kamino and used the borrowed liquidity to manipulate stablecoin pool ratios on Allbridge Core.
How the Allbridge Core Attack Happened
The exploit followed a multi-step process involving liquidity manipulation and rapid asset movement.
The attacker first obtained a large flash loan, allowing them to access significant capital without providing traditional collateral. The borrowed USDC was then used to execute large swaps between USDC and USDT within Allbridge Core’s Solana liquidity pools.
This activity distorted the balance between the stablecoins inside the pool. As a result, the attacker was able to withdraw assets at an unfavorable exchange rate for the protocol but a profitable rate for the attacker. After completing the transaction, the flash loan was repaid within the same blockchain transaction.
Flash loan attacks have become a recurring threat across DeFi because they allow attackers to temporarily control large amounts of capital. When combined with vulnerabilities in pricing mechanisms, liquidity pools, or smart contract logic, these loans can create opportunities for rapid financial manipulation.
Stolen Funds Move From Solana to Ethereum
Following the exploit, blockchain monitoring platforms tracked the stolen assets as they moved from Solana to Ethereum. Security companies PeckShield and CertiK reported that the attacker bridged the funds across networks after draining the affected pools.
Moving assets between blockchains is a common tactic used by attackers attempting to complicate investigations. Ethereum’s larger ecosystem and the availability of multiple privacy-focused tools can make fund tracing more challenging.
However, blockchain transactions remain publicly visible, allowing security firms and independent analysts to continue monitoring wallet activity. Investigators are expected to track further movements and identify whether the attacker attempts to convert or distribute the stolen assets.
Allbridge Response and Liquidity Provider Warning
Following the attack, Allbridge Core paused its operations and began reviewing the affected infrastructure. The team also encouraged liquidity providers to withdraw funds from impacted pools while the investigation remained active.
Allbridge stated that the pool imbalance created a temporary arbitrage opportunity following the exploit. The project requested that users who benefited from the imbalance consider returning funds, with recovered assets intended to support affected liquidity providers.
The response reflects a growing trend among DeFi platforms that rely on community cooperation after security incidents. While blockchain transactions cannot easily be reversed, protocols often attempt to recover funds through negotiations with attackers, white-hat interventions, or voluntary returns.
Cross-Chain Bridge Security Concerns Increase
The Allbridge Core exploit adds to a long list of security incidents affecting blockchain bridges. These platforms remain attractive targets because they hold significant liquidity and connect multiple networks through complex smart contract systems.
Cross-chain infrastructure has become a critical component of the crypto economy. Users rely on bridges to move assets between ecosystems such as Solana, Ethereum, and other blockchain networks. However, the complexity of these systems creates additional attack surfaces.
Security experts have repeatedly warned that bridge protocols require stronger auditing procedures, improved monitoring systems, and more advanced risk controls. The latest Allbridge incident reinforces concerns that liquidity management mechanisms remain vulnerable to manipulation.
Previous Security Challenges for Allbridge
The latest incident also brings renewed attention to Allbridge’s security history. The protocol previously experienced an exploit in 2023, making this another significant security challenge for the project.
Repeated attacks against established DeFi platforms demonstrate the importance of continuous security upgrades. Even protocols that have undergone audits can face new vulnerabilities as blockchain ecosystems evolve and attackers develop more advanced techniques.
For users, the incident serves as another reminder of the risks associated with decentralized finance platforms. While DeFi offers greater accessibility and financial innovation, users remain exposed to smart contract vulnerabilities and protocol-level failures.
Impact on Solana and DeFi Market Confidence
The exploit arrives during a period of increasing adoption for Solana-based decentralized applications. Although the attack targeted Allbridge Core rather than the Solana blockchain itself, incidents involving major protocols can influence investor sentiment across the ecosystem.
Market analysts typically view bridge vulnerabilities as ecosystem-wide concerns because cross-chain applications often serve as important liquidity gateways. A major breach can reduce user confidence and increase demand for stronger security standards.
At the same time, rapid detection by blockchain security firms demonstrates the growing maturity of crypto monitoring infrastructure. Companies such as PeckShield and CertiK continue to play a key role in identifying suspicious transactions and helping protocols respond quickly.
Conclusion
The Allbridge Core exploit draining $1.65 million from Solana liquidity pools has once again placed cross-chain bridge security under scrutiny. The attacker used a flash loan strategy to manipulate stablecoin pool balances before transferring the stolen assets from Solana to Ethereum.
Allbridge Core has paused operations and launched an investigation while security teams continue tracking the stolen funds. Although blockchain transparency allows analysts to follow transaction movements, recovering exploited assets remains a major challenge for DeFi platforms.
The incident highlights a broader lesson for the cryptocurrency industry: as cross-chain adoption expands, security infrastructure must evolve alongside innovation. For decentralized finance to achieve long-term growth, protocols will need stronger safeguards, better monitoring systems, and more resilient smart contract designs.

Leave a Reply