Allbridge Core, a cross-chain bridge protocol, was paused on July 19 after an attacker drained roughly $1.65 million from its Solana liquidity pools. The exploit used a flash loan of about $1.12 million USDC from the lending protocol Kamino to repeatedly swap between USDC and USDT, skewing pool ratios before withdrawing funds.
How the attack worked
On-chain data from PeckShield and CertiK shows the attacker executed rapid atomic swaps that exploited a gap in the stable pool's pricing mechanism. The flash loan from Kamino allowed the attacker to manipulate the pool's balance without upfront capital. After the swaps, the stolen funds were bridged from Solana to Ethereum.
The post-mortem traced a 948,927.53 USDT withdrawal and a $2.24 million USDC movement through Allbridge as liquidity shifted during the attack. The primary weakness: the stable pool pricing could be manipulated in a narrow window because the protocol lacked time-weighted average price (TWAP) checks, dynamic fee multipliers, and circuit breakers that would have stopped swaps when an imbalance crossed a threshold.
Solana's speed worked against the protocol
Solana's high throughput allowed the attacker to execute atomic or near-atomic actions in a short window, reducing the chance of detection by slow-moving guards. The exploit highlights a tension between speed and security: the same performance that makes Solana attractive for DeFi also compresses the time available for protective measures to kick in.
What happens next
Allbridge Core remains paused as the team investigates. The protocol has not announced a timeline for resuming operations or a plan for recovering the stolen funds. The incident adds to a growing list of bridge exploits this year, and the lack of basic safeguards like TWAP and circuit breakers is likely to draw scrutiny from users and auditors alike.


