Another week, another Solana exploit, and this one comes with an uncomfortable sense of déjà vu. Allbridge, the company behind the cross-chain stablecoin bridge Allbridge Core, has paused its protocol after an attacker drained roughly $1.65 million from its Solana deployment, using a technique the project has already been burned by once before.
Allbridge team wrote on X. “We have paused the protocol as a precaution while we investigate. If you have liquidity in affected pools, please withdraw now.”
How the Attack Worked
According to on-chain analysis from Onchain Lens and PeckShield, the exploit was a textbook flash-loan price manipulation: an attack that borrows a large sum, distorts a market within a single transaction, profits from the distortion, and repays the loan before the block closes.
The attacker took out a $1.12 million USDC flash loan from the Solana lending protocol Kamino. They then executed rapid USDC/USDT swaps through Allbridge’s pools, deliberately skewing the ratio between the two stablecoins. Because Allbridge Core prices liquidity withdrawals off that ratio, the imbalance let the attacker withdraw liquidity at manipulated rates, repay the $1.12 million loan, and walk away with the difference. The stolen funds were then bridged from Solana to Ethereum and swapped into ETH, before some were routed toward privacy pools to frustrate tracing.
The mechanics matter because they explain why bridges keep getting hit. Allbridge Core holds native stablecoin liquidity pools on each chain to enable wrapped-token-free transfers, which is efficient, but it means the protocol is only ever as safe as the math governing those pools. Get the pricing logic wrong under adversarial conditions, and the liquidity that makes the bridge useful becomes the liquidity an attacker drains.
The Unusual Plea to Arbitrageurs
Allbridge’s response contained a revealing wrinkle. The pool imbalance the attacker created did not just benefit the attacker — it briefly opened a profitable arbitrage window for anyone watching, meaning ordinary traders may have unknowingly scooped up value that ultimately belongs to the bridge’s liquidity providers.
“The resulting pool imbalance created a temporary positive arbitrage window,” the team wrote. “If you took advantage of it, please consider returning funds to the address below – this will go directly toward compensating affected LPs.” It published a collection address for voluntary returns.
It is a polite request with no enforcement behind it, and it underscores an awkward reality of pool-manipulation attacks: the damage radiates beyond the hacker. The people who arbitraged a distorted pool did nothing illegal in any obvious sense, they took a trade the market offered, but the funds still came out of LPs’ pockets.
Commenting on the exploit, Gonçalo Magalhães, Head of Security at Immunefi, shared, “The flash loan supplied size. The design question is whether a pool charges for imbalance. Well-built stable pools price off a single invariant, so swaps grow costlier with size due to an imbalance fee. The intent is that skewing the pool costs more than the skew returns. Where that penalty is absent, and withdrawal pricing reads reserves that a single large swap just moved, capital alone is sufficient for achieving significant damage. Our 2026 research puts flash-loan losses under 1% of the DeFi total, down from 54% in 2020. What remains sits in pools where imbalance is cheap and the exit prices off those reserves. The bounty offer is the right call, and the window for it is short. Negotiated returns work more often than the industry assumes.”
History Repeats: The 2023 Precedent
The detail that stings is the precedent. In April 2023, Allbridge Core was exploited through a strikingly similar flash-loan attack on its BNB Chain pools, in which the attacker acted as both liquidity provider and swapper to manipulate swap prices, draining roughly $570,000 across BUSD and USDT.
The protocol recovered most of that, around $465,000, through a white-hat arrangement, paused, rewrote parts of its design, and relaunched with new safeguards including a “Rebalancer Authority” meant to correct exactly the kind of pool imbalance that has now been weaponized again. That history cuts both ways. It offers a genuine reason for optimism about recovery: Allbridge has negotiated a hacker into returning funds before, and has a template for doing it again. But it also raises the harder question of why a protocol that was drained via flash-loan pool manipulation in 2023 was drained via flash-loan pool manipulation in 2026.
Part of a Brutal Stretch for Bridges and Solana
The exploit does not stand alone. By one industry count, it is at least the sixth attack on a cross-chain bridge since May. Bridges remain among the most targeted infrastructure in crypto for a simple reason: they concentrate large pools of assets in one place to back transfers, making them a honeypot where a single logic flaw can unlock millions.
It also lands during a punishing run for Solana DeFi specifically. Just days ago, the Solana lending protocol DeFiTuna was exploited for $580,000, leaving its USDC pool in deficit, and that followed far larger blows earlier in the year, including Drift’s roughly $285 million exploit and Step Finance’s treasury breach. The pattern, once again, is not a failure of Solana’s base layer, which has kept running throughout; it is the security of the applications and bridges built on top of it. Deep stablecoin liquidity is what makes Solana attractive to build on, and it is also what makes its DeFi such a rewarding target.
What to Watch
Three things will determine how this ends. First, whether the stolen ETH moves toward centralized-exchange deposit addresses, which on-chain trackers are monitoring — any such movement would open a narrow window for a freeze. Second, whether Allbridge can once again negotiate a white-hat return, a harder task with a larger sum spread across two ecosystems and partly obscured by privacy pools. Third, and most important for the protocol’s future, whether Allbridge publishes a full post-mortem explaining how a 2023-style attack succeeded in 2026, and whether it makes affected LPs whole.
For users, the immediate guidance is Allbridge’s own: anyone with liquidity in the affected pools should withdraw, and the protocol remains paused pending investigation. For the industry, the lesson is the one bridges keep teaching and the market keeps re-learning — the code that moves value between chains is only as trustworthy as its behaviour on its worst day.
Also Read: Crypto Loses Over $20M in a Week as Ostium, Across, Cascade Get Hacked
