Allbridge Core Pauses Protocol After $1.1 Million Exploit
Allbridge Core Pauses Protocol After $1.1 Million Exploit – Stablecoin Pool Attack Adds to July’s $57.8 Million in Crypto Losses
Key Takeaways
- Allbridge Core paused its protocol after an exploit on its Solana-based stablecoin pools.
- Blockchain tracker Onchain Lens estimates losses at more than $1.1 million.
- The attacker used a $1.12 million USDC flash loan from Kamino to manipulate the USDC/USDT pool.
- Crypto exploits in July 2026 have resulted in $57.8 million in losses.
- Allbridge has asked traders who profited from the imbalance to return funds to compensate affected liquidity providers.
Flash Loan Exploit Targets Allbridge Core on Solana
Allbridge Core has paused its protocol following a flash loan exploit that targeted its stablecoin liquidity pools on Solana. The incident was first reported by blockchain analytics firm Onchain Lens, which estimates that the attacker extracted more than $1.1 million.
According to Onchain Lens, the exploit involved a $1.12 million USDC flash loan obtained from Kamino. The attacker used the borrowed funds to manipulate the USDC/USDT stablecoin pool on Allbridge Core. Through a series of rapid swaps, the pool’s token ratios were distorted, temporarily changing the relative pricing inside the pool.
Once the imbalance was created, the attacker withdrew liquidity at inflated values. The flash loan was repaid within the same transaction, a common feature of such attacks that allows large amounts of capital to be deployed without long term exposure. Onchain Lens reported that the largest single withdrawal identified during the exploit amounted to $2.24 million in USDC.
The stolen funds were subsequently routed through privacy protocols, according to the tracker, in an apparent attempt to obscure their movement.
Protocol Paused as Investigation Begins
In response to the incident, Allbridge Core paused its protocol as a precautionary measure. The team confirmed that the imbalance in the stablecoin pool briefly opened an arbitrage window, allowing some traders to profit from distorted pricing.
Allbridge stated that it has launched an investigation into the exploit. The team also publicly requested that traders who benefited from the temporary imbalance voluntarily return the funds. According to the company, returned assets would be used to compensate affected liquidity providers.
In its communication, Allbridge published a specific address designated to receive returned funds. The stated objective is to return all affected funds to liquidity providers who experienced losses as a result of the exploit.
At the time of reporting, Allbridge had not provided additional technical details about the vulnerability that enabled the manipulation.
Part of a Broader Wave of Crypto Exploits in July 2026
The Allbridge incident adds to a growing number of attacks targeting crypto protocols in July 2026. According to the figures cited in the report, exploits across the sector have resulted in $57.8 million in losses during the month.
Flash loan attacks remain a recurring method in decentralized finance. They allow attackers to borrow substantial amounts of capital within a single transaction, provided the loan is repaid before the transaction concludes. When combined with liquidity pool manipulation, this mechanism can create short lived pricing distortions that are difficult to counter in real time.
In this case, the manipulation of a stablecoin pair, USDC and USDT, underscores that even pools composed of assets designed to maintain price parity can be vulnerable if liquidity ratios are temporarily skewed.
For users who provide liquidity to decentralized protocols, such incidents can directly affect deposited assets. When liquidity is withdrawn at distorted prices, remaining providers may absorb losses until balances are restored or compensation is arranged.
Previous Flash Loan Incident in 2023
This is not the first time Allbridge has faced a flash loan related exploit. In April 2023, an attacker targeted an Allbridge pool on the BNB network. That incident resulted in losses of approximately $570,000.
While the technical details of the 2023 exploit differ from the current case, both incidents involved liquidity pool manipulation enabled by flash loans. The recurrence highlights the ongoing security challenges faced by cross chain and liquidity focused protocols operating in decentralized finance environments.
For users monitoring protocol risk, repeated exploit history can be a relevant factor when evaluating exposure to specific platforms.
Implications for Liquidity Providers and Market Participants
For liquidity providers on Allbridge Core, the immediate impact is operational disruption due to the protocol pause. Until the investigation concludes and services are restored, users may face limited access to liquidity functions on the platform.
The incident also illustrates how temporary imbalances can create arbitrage opportunities. While some traders were able to profit during the brief window, Allbridge has requested that such gains be returned to help offset losses experienced by liquidity providers.
In the broader crypto market, cumulative exploit losses such as the reported $57.8 million in July 2026 contribute to ongoing scrutiny of decentralized finance security practices. For users of crypto based financial services, including those who move assets between platforms, operational pauses and liquidity events can affect access and transaction timing.
Our Assessment
Allbridge Core paused its protocol after a flash loan exploit led to losses exceeding $1.1 million on its Solana based stablecoin pools. The attacker used a $1.12 million USDC flash loan to manipulate pool ratios and withdraw funds at inflated values. The incident forms part of $57.8 million in crypto exploit losses reported for July 2026. Allbridge has opened an investigation and requested the return of profits generated from the temporary imbalance to compensate affected liquidity providers.
