Allbridge Core, a stablecoin routing protocol, paused operations this week after a flash-loan exploit wiped roughly $1.65 million from its USDC/USDT pool on Solana. The attack, which took place over the weekend of July 19–20, was first reported by The Block. The protocol has urged liquidity providers to pull their funds and shared a return address in hopes of a voluntary refund.
How the exploit worked
The attacker borrowed $1.12 million USDC via a flash loan from Kamino on Solana. That single transaction let them manipulate the Allbridge Core stable pool — draining a peak of about $2.24 million USDC in one withdrawal. The net loss came to $1.65 million because the flash loan itself was repaid within the same block, a standard mechanic in these attacks. On-chain data shows the maneuver was quick and precise.
Funds moved to Ethereum, privacy tools
After pulling the stablecoins, the attacker bridged funds from Solana to Ethereum and routed them through privacy protocols. That makes tracing harder, though the return address Allbridge published — 0x01a494079DCB715f622340301463cE50cd69A4D0 — suggests the team is leaving the door open for the hacker to send the money back voluntarily.
Protocol’s response: withdrawals and a refund address
Allbridge Core paused operations shortly after the incident. The team issued a statement urging all liquidity providers to withdraw from affected pools. They also shared the return address publicly, a move that sometimes works in DeFi — a few past exploiters have returned funds after negotiations or pressure. So far, no refund has been reported.
What’s next
Allbridge hasn't given a timeline for resuming normal operations. For now, LPs who haven't withdrawn are sitting on potentially vulnerable positions. The bigger question is whether the attacker will engage with the return address or if the $1.65 million is gone for good.



