Logo
My Crypto News AI

Flash Loan Attack Drains $1.65M From Allbridge on Solana; Funds Bridged to Ethereum

Allbridge Core, a cross-chain bridge protocol, was exploited for approximately $1.65 million in a sophisticated flash loan attack on Solana, with the attacker quickly moving stolen funds to Ethereum before obscuring the trail through privacy-mixing services. The incident highlights a critical vulnerability in how decentralized finance (DeFi) protocols manage liquidity pools, even when the underlying smart contracts remain uncompromised.

What Exactly Happened in the Allbridge Exploit?

The attack followed a textbook flash loan playbook, executed entirely within a single blockchain transaction. On-chain investigators at Onchain Lens traced the exploit step-by-step: the attacker borrowed $1.12 million in USDC (a stablecoin pegged to the US dollar) through Kamino Finance, a lending protocol on Solana. The attacker then rapidly swapped that USDC for USDT (another stablecoin) within Allbridge's stablecoin pool, artificially distorting the exchange rate between the two assets. This temporary imbalance created an opportunity to withdraw liquidity at favorable, skewed rates. The attacker extracted roughly $1.1 million in profit, repaid the flash loan in full within the same transaction, and walked away clean.

The single largest withdrawal tied to the hack reached $2.24 million in USDC, according to Onchain Lens. Security firm PeckShield's monitoring put the total exploit impact closer to $1.65 million, and confirmed that the attacker bridged the stolen funds from Solana over to Ethereum shortly after the attack. The stolen assets were then passed through privacy protocols, making them considerably harder to trace and significantly lowering the odds of a clean recovery.

Why Does This Matter for Liquidity Providers?

This exploit reveals a risk that many liquidity providers (LPs) overlook. A liquidity provider deposits assets into a pool in exchange for a share of trading fees. When an attacker manipulates the pool's pricing mechanism, LPs can suffer losses even if the bridge contract itself remains secure and functional. The incident shows that DeFi protocols face risks not only from smart contract bugs but also from pool pricing weaknesses and temporary imbalances that attackers can exploit before the protocol reacts.

Allbridge paused its Core protocol immediately upon detecting the exploit and urged all liquidity providers to withdraw their funds. The team has not yet published a full post-mortem or provided a timeline for resuming normal operations. In a goodwill gesture, Allbridge publicly appealed to arbitrage traders who captured profits from the pool imbalance to voluntarily return those funds to a dedicated wallet address. Any returned funds would go directly toward compensating affected LPs, though this remains a voluntary appeal rather than a guaranteed recovery mechanism.

How to Protect Yourself as a Liquidity Provider

  • Monitor Emergency Announcements: Follow official Allbridge communication channels and set up alerts for protocol updates, especially any announcements about security incidents or operational pauses.
  • Watch for Sudden Pool Ratio Changes: Track the exchange rates and asset ratios in pools where you have liquidity deposited; unusual swings can signal an attack or manipulation attempt.
  • Track Large Flash Loan Activity: Flash loans are legitimate tools but can be weaponized; monitor on-chain data for unusually large flash loan borrows that coincide with your pool's activity.
  • Act Quickly on Withdrawal Timing: If a protocol experiences a security incident, withdrawing liquidity promptly reduces your exposure to further losses or complications during the investigation phase.

The Allbridge incident also serves as a reminder that compensation for affected users depends on recovered funds, returned arbitrage profits, or protocol treasury support. Until a formal compensation plan is confirmed, affected LPs face uncertainty about whether they will be made whole.

A Broader Pattern of Cross-Chain Bridge Vulnerabilities

This latest exploit adds to a growing list of attacks on cross-chain bridge protocols, which have become prime targets for hackers due to the large pools of locked liquidity they manage. Bridges like Allbridge facilitate the transfer of assets between different blockchain networks, a critical function in the decentralized finance ecosystem. However, their complexity often introduces security risks. According to data from DeFiLlama, over $2 billion has been lost to cross-chain bridge exploits since 2021.

Security experts recommend that users who have deposited assets into Allbridge immediately check their wallet balances and revoke any smart contract approvals linked to the protocol. Users should also be cautious of phishing attempts that may follow such incidents, as cybercriminals often exploit the confusion and urgency surrounding a hack to launch social engineering campaigns.

The Allbridge exploit investigation is ongoing, and a formal post-mortem report is likely once the team has a complete picture. Traders and LPs should watch for potential smart contract fixes, protocol upgrades, updates on fund recovery, and any concrete compensation plan for affected liquidity providers. For now, affected users should follow Allbridge's official channels closely while the team works toward mitigation and possible recovery.