Allbridge loses 1.65 million dollars in flash loan attack
The cross-chain bridge protocol Allbridge Core was drained for 1.65 million dollars (roughly €1.45 million) on 19 July. The attacker used a flash loan to manipulate a stablecoin pool and moved the loot from Solana to Ethereum. The protocol has been paused.
Cross-chain bridges remain one of the most vulnerable parts of DeFi. On 19 July, Allbridge Core was drained for around 1.65 million dollars (roughly €1.45 million).
How the attack worked
Using a flash loan, the attacker borrowed around 1.12 million dollars from the Solana-based platform Kamino and used it to manipulate a stablecoin pool, rapidly swapping USDC for USDT. By throwing the pool off balance, the attacker extracted more value than they put in. The loot was then routed through privacy protocols and bridged to Ethereum. Security firms PeckShield and CertiK confirmed the trail.
The protocol's response
Allbridge paused the protocol immediately and urged users to withdraw liquidity from the affected pools. The team announced it would reimburse all affected funds, and asked anyone who profited from the resulting arbitrage to return those gains.
The bigger picture
The amount is small; the pattern is not. Bridges and pools hold a lot of capital and run on complex logic, which makes them a structural target. In 2026, losses from DeFi exploits already run into the billions. Flash loans are not a bug but a feature — they only turn dangerous once a pool is set up too thin or too naively.
What this means for you
If you use DeFi, treat bridges and yield pools as the riskiest part of your portfolio. Diversify, never stake more than you can afford to lose, and check whether a protocol has been audited recently by a reputable firm — though even an audit is no guarantee. A yield that looks too good is often payment for risk you cannot see at first glance.
This article is informational and does not constitute financial advice.
Sources: PeckShield, CertiK, Allbridge. Last checked: 20 July 2026.
