Allbridge paused its Core cross-chain protocol on July 20, 2026 after an attacker drained approximately $1.65M from its Solana stablecoin pools. The twist is not the flash loan mechanic, which is by now routine; it is that Allbridge already shipped a structural fix for this exact attack class after a 2023 incident, and the Solana pool was configured in a way that quietly nullified it.
How the drain worked
The attacker took a roughly $1.12M USDC flash loan from Kamino Finance and ran a series of rapid USDC to USDT and USDT to USDC swaps against Allbridge's Solana pool. Because the pool priced liquidity from its own internal USDC to USDT ratio, the swap sequence pushed that ratio far off peg inside the pool, even though the external market price of both stablecoins barely moved. The attacker then withdrew liquidity at the distorted internal rate, extracting more value than they deposited, and repaid the Kamino loan in the same transaction. Around 1.118M USDC and 538k USDT were bridged out of Solana and consolidated on a single Ethereum address, with about $1.63M traced on-chain.
Why the 2023 fix did not save this pool
Allbridge was hit by a very similar exploit on BNB Chain in April 2023, losing about $573k, most of which was later returned through a white-hat arrangement. The response was a design change: each Core pool should hold only ONE stablecoin per chain, so there is no internal USDC to USDT ratio inside a single pool for a swap sequence to distort. If the rule holds, the flash-loan-and-swap pattern has nothing to bend. The Solana pool broke that rule. It was configured with both USDC and USDT in the same pool, restoring exactly the internal ratio the fix was meant to eliminate. The protocol-level defense existed; the deployment did not apply it. That is a configuration failure, not a novel exploit, which is arguably worse because it means the security model was correct on paper and wrong in production.
What LPs should do and what it means for bridge risk
If you are an LP in an affected Allbridge Solana pool, the practical move is to withdraw as Allbridge itself has advised, accept the pro-rata haircut from the drained balance, and reassess before redepositing. Non-pool bridging routes are resuming, but the specific Solana stablecoin pools should be treated as unsafe until Allbridge publishes a post-mortem and confirms the pool has been rebuilt to the one-stablecoin-per-chain rule. The traced funds and the 2023 white-hat precedent are mildly encouraging, but they do not change the LP calculus today: recovery is a negotiation that can take weeks or months, is not guaranteed, and even in the best 2023 case some funds never came back.
The broader lesson for cross-chain users is that a bridge is not one system, it is a set of per-chain deployments, each of which can silently drift from the security assumptions of the whole. Audits and design fixes protect the intended configuration. They do not protect a pool that was launched or migrated with the wrong parameters. When you evaluate bridge risk, the deployment on the specific chain and specific pool you are using matters more than the protocol's overall reputation, and second-time incidents on the same protocol deserve heavier weighting than first-time ones.
What Koinlytics tracks: exposure to bridge protocols and stablecoin LP positions across chains, so you can see at a glance which of your holdings sit inside a pool like the one Allbridge just paused.
Koinlytics