
Allbridge pauses Allbridge Core after reported $1.65M Solana stablecoin pool exploit
Attackers allegedly used a Kamino USDC flash loan, then bridged funds to Ethereum and moved them into privacy pools.
Allbridge has paused its Allbridge Core cross-chain stablecoin bridge after a “security incident” that reportedly drained $1.65 million from its Solana deployment on Sunday. The team urged liquidity providers in affected pools to withdraw while it investigates, as stolen funds were allegedly bridged to Ethereum and routed into privacy pools.
Key Takeaways
- Allbridge halted Allbridge Core after a “security incident” tied to a reported $1.65 million drain on Sunday.
- The exploit hit the protocol’s Solana deployment, and the stolen funds were allegedly bridged to Ethereum before being moved into privacy pools.
- Onchain Lens traced the attack to a $1.12 million USDC flash loan from Kamino and rapid USDC/USDT swaps that distorted a stablecoin pool exchange rate.
- Allbridge said the imbalance created a temporary arbitrage window and asked any beneficiaries to return funds to help compensate affected liquidity providers.
Allbridge Core Paused After Reported $1.65M Solana Exploit
Allbridge paused Allbridge Core after what it described as a security incident that reportedly drained $1.65 million on Sunday. The company’s posture was not “we fixed it,” it was “we’re stopping the machine.” That matters for anyone exposed to the affected pools because it frames this as an active risk-management event, not a closed post-mortem.
In its public message, Allbridge told users exactly what it wanted them to do: reduce exposure. “Allbridge Core is experiencing a security incident. We have paused the protocol as a precaution while we investigate. If you have liquidity in affected pools, please withdraw now.” The instruction is blunt because the failure mode here is not theoretical. When a pool’s pricing can be pushed offside, LPs are the inventory that gets marked down.
Two uncertainties hang over the headline number. The $1.65 million figure is described as “reportedly” drained, and the exact calendar date for “Sunday” is not specified beyond the day-of-week reference. For traders and LPs, that means you treat the magnitude as directional until there is an onchain accounting or a protocol post-mortem that pins down the exact affected pools and net loss.
How the Flash-Loan Swap Loop Distorted the Stablecoin Pool
The exploit path described onchain is a classic liquidity-pool distortion trade dressed in bridge clothing. Onchain Lens described the attacker taking a $1.12 million USDC flash loan from Kamino, then running rapid USDC/USDT swaps that distorted the Allbridge Core stablecoin pool’s exchange rate. With the pool’s internal pricing pushed away from fair value, the attacker could withdraw liquidity at manipulated rates, repay the flash loan, and keep the difference.
Mechanically, the key ingredient is temporary size. Flash loans let an attacker borrow large capital and return it within the same transaction flow, so they can force a pool into an imbalanced state without needing to hold that capital long term. In stablecoin pools, where users expect tight pricing and low slippage, the system’s assumptions can become its weakness. If the pool’s pricing or withdrawal math can be influenced by rapid swaps, the attacker can turn “momentary mispricing” into “realized loss” for LPs.
What stands out here is that the described sequence is not about breaking cryptography or stealing keys. It is about exploiting how the pool responds under stress when a large actor pushes the exchange rate around quickly. That’s why these events keep recurring across DeFi. The attacker doesn’t need persistence. They need one window where the pool’s rules pay out more than they should.
Funds Bridged to Ethereum and Routed Into Privacy Pools
Allbridge said the incident affected its Solana deployment, and that the attacker had already bridged stolen funds from Solana to Ethereum before moving them into privacy pools. That cross-chain hop is not just a detail for the incident report. It changes the recovery geometry.
Once funds move across chains, the investigation becomes a coordination problem. You are no longer tracking a single environment with one set of tooling and counterparties. You are tracking a flow that crosses execution layers and liquidity venues, then disappears into privacy infrastructure designed to break link analysis. Even if the initial exploit path is well understood, attribution and recovery get harder when the trail is intentionally degraded.
Allbridge also acknowledged a second-order effect that traders will recognize immediately. The protocol said the pool imbalance created a temporary positive arbitrage window and asked anyone who benefited to consider returning funds to compensate affected LPs: “The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage of it, please consider returning funds… this will go directly toward compensating affected LPs.”
That request is revealing. It implies the damage may not be fully concentrated in the attacker’s wallet. Some portion of the loss could have been socialized through the pool’s mispricing and captured by third parties who simply traded the imbalance. Voluntary returns can help, but they are not a control surface. They are a hope-based recovery channel.
Reopen Timing, Post-Mortem Details, and LP Compensation Signals
The market question now is not whether an exploit happened. It is what Allbridge can credibly do next, and how quickly it can do it without reopening the same hole.
The first gating item is a post-mortem that identifies the exact affected pools and asset pairs on Solana, plus the remediation steps required before reopening Allbridge Core. Without that specificity, LPs cannot quantify exposure and bridge users cannot assess whether the risk is isolated to one stablecoin pool design or broader to the protocol’s Solana-side deployment.
The second signal is onchain confirmation of returned funds tied to Allbridge’s request for arbitrage beneficiaries to send funds back for LP compensation. If returns show up, it suggests at least some of the loss was captured by opportunistic flow rather than exclusively by the attacker. If returns do not materialize, the compensation burden shifts back toward the protocol’s balance sheet decisions or a formal reimbursement plan.
The third is whether Allbridge can trace or freeze assets after the reported move from Solana to Ethereum and into privacy pools. The story as described already flags the constraint. Privacy pools reduce traceability, and the specific services used were not identified.
Finally, traders should watch for a concrete timeline for resuming bridging and any formal reimbursement or compensation plan for affected LPs. A pause is a circuit breaker. The reopening plan is where credibility gets priced.
What This Incident Signals for Solana/Ethereum Stablecoin LP Risk
I’m not treating this as a one-off glitch. The described path is a familiar pattern: flash-loan size, rapid stablecoin swaps, distorted pool pricing, then liquidity withdrawal at manipulated rates with the loan repaid inside the flow. That is the same class of failure that keeps showing up in bridge-adjacent liquidity pools because the pools are the collateral surface area.
There’s also history here. Allbridge was exploited in April 2023 for $573,000 via a flash loan attack on its BNB Chain pool, draining $289,900 in BUSD and $290,900 in USDT. Different chain, same family of attack. When a protocol has repeated exposure to flash-loan-and-price-manipulation dynamics, the market stops giving it the benefit of “edge case.” It starts pricing it as a recurring risk factor.
Scenario one is the clean containment path. Allbridge publishes a post-mortem that narrows the blast radius to specific Solana stablecoin pools, ships a remediation that directly addresses the exchange-rate distortion vector, and reopens with clear constraints. Confirmation for this scenario is specificity: named pools, named fixes, and a reopening that does not rely on vague assurances.
Scenario two is partial containment with messy economics. The protocol can fix the technical issue, but LP outcomes depend on whether any arbitrage beneficiaries return funds and whether Allbridge offers a formal compensation plan. The confirmation point is onchain: do meaningful returns arrive, and does the team commit to a defined reimbursement framework rather than an open-ended request.
Scenario three is the credibility drawdown. Funds routed from Solana to Ethereum and into privacy pools stay unrecovered, returns do not show up, and reopening drags because the team cannot confidently prevent a repeat. The invalidation point for this bearish operational scenario is a fast, detailed post-mortem paired with a concrete reopen timeline.
The core thesis is simple: until Allbridge can name the affected pools, explain the exact remediation, and show whether any funds are recoverable after the privacy-pool routing, the pause reads as ongoing risk management rather than a contained incident.