Loading market data...

Allbridge Suspends Platform After $1.65M Flash Loan Exploit

Allbridge Suspends Platform After $1.65M Flash Loan Exploit

Allbridge, a cross-chain bridge protocol, has suspended its Core platform after a flash loan attack drained $1.65 million from its USDC/USDT liquidity pool. The exploit, which targeted a vulnerability in the platform's liquidity mechanism, forced the team to halt operations while they investigate.

How the attack worked

The attacker used a flash loan — a type of uncollateralized loan that must be repaid within a single transaction — to manipulate the liquidity pool. By borrowing a large amount of assets, the attacker was able to distort the pool's price ratio and drain funds before the loan was returned. This is a well-known vulnerability in decentralized finance, but it continues to catch protocols off guard.

Allbridge confirmed the incident on social media, stating that the exploit affected its Core platform's USDC/USDT pool. The company said it is working with security firms to trace the stolen funds and identify the attacker.

Platform suspension and user impact

In response to the attack, Allbridge suspended its Core platform to prevent further losses. Users who had funds in the affected pool are unable to withdraw or transfer assets until the platform is restored. The company has not yet announced a timeline for resuming operations.

The exploit is the latest in a string of flash loan attacks that have hit DeFi protocols in recent months. While the total value locked in Allbridge's Core platform is not publicly known, the $1.65 million loss represents a significant hit for the project.

Allbridge says it is conducting a thorough security review and will share more details once the investigation is complete. The team has not said whether it plans to reimburse affected users or if the platform will undergo a major redesign to prevent similar attacks.

The company has not announced when the Core platform will resume operations.