Allbridge Pauses Protocol After $1.65M Exploit Drains Stablecoin Liquidity Pools
Allbridge Core, a cross-chain stablecoin bridge, has suspended operations following a security exploit that drained approximately $1.65 million from its stablecoin liquidity pools. Blockchain security firm PeckShield reported the incident, noting that the attacker bridged the stolen funds from Solana to Ethereum. Allbridge confirmed the exploit and temporarily paused the protocol while investigating. The project urged users with liquidity in affected pools to withdraw their funds immediately. The exploit created a temporary positive arbitrage opportunity due to pool imbalance; Allbridge asked anyone who profited to voluntarily return the funds, which would be used to compensate affected liquidity providers. Onchain Labs detailed that the attack began with a $1.12 million USDC flash loan from Kamino on Solana. The attacker used rapid USDC and USDT swaps to manipulate Allbridge Core’s stablecoin pool ratios, then withdrew liquidity at distorted rates, repaying the flash loan within the same transaction. The stolen assets were later moved through privacy protocols for mixing. This marks the second known exploit for Allbridge; in April 2023, the protocol lost around $573,000 in a flash loan attack on BNB Chain that exploited a smart contract bug. Cross-chain bridges continue to be prime targets for hackers. Recent incidents include Syndicate Labs losing $330,000 in April, the Verus-Ethereum bridge losing over $11 million in May (though most funds were recovered), and Taiko urging users to withdraw assets after a $1.7 million theft in June.