Allbridge suspended its Core Bridge on Monday after an attacker exploited a price-manipulation vulnerability in its Solana-based stablecoin pools, draining roughly $1.65 million before moving the funds across chains to Ethereum. The incident is a sharp reminder that cross-chain infrastructure remains among the most exposed surfaces in decentralized finance — and that flash loan mechanics, now a well-documented attack vector, continue to find new victims.
According to analysis from multiple security firms, the attacker bootstrapped the operation with a $1.12 million flash loan drawn from Kamino, a lending protocol operating on Solana. Flash loans are uncollateralized borrowing instruments that must be borrowed and repaid within a single transaction block — but their atomic, zero-collateral nature makes them powerful tools for anyone looking to temporarily amplify capital and manipulate on-chain pricing mechanisms.
The mechanics were precise and deliberate. By deploying over a million dollars in borrowed liquidity in a single transaction, the attacker was able to skew the pricing ratios inside Allbridge's Solana stablecoin pools — artificially distorting the exchange rate to a point where the protocol's own logic could be turned against it. That kind of pool imbalance, if engineered carefully, allows an attacker to extract more value than they deposit, essentially siphoning reserves at a manipulated price. The borrowed Kamino funds were repaid within the same transaction, leaving the attacker with a net profit funded entirely by Allbridge's liquidity providers.
What made the attack particularly difficult to contain in real time was its multi-chain nature. Once the exploit had extracted value from the Solana-side pools, the proceeds were bridged over to Ethereum — placing them on a different ledger, under a different set of monitoring tools, and further from immediate recovery efforts. Cross-chain bridges have long been flagged by security researchers as uniquely dangerous infrastructure: they must reconcile state across two or more independent blockchains, and any discrepancy in that reconciliation can be weaponized. In this case, the bridge itself became the exit route.
Allbridge's decision to halt the Core Bridge was the appropriate emergency response, buying time to assess the damage and prevent further exploitation. Pausing bridge contracts is a well-established incident response tactic in decentralized finance, though it carries its own costs — users with assets in transit or locked in pools face uncertainty, and the reputational toll of a halt compounds the financial damage of the exploit itself. The protocol has not yet publicly detailed a recovery timeline or compensation plan for affected liquidity providers, based on information available at the time of publication.
The Kamino flash loan angle deserves separate scrutiny. Kamino itself was not exploited — the protocol functioned exactly as designed, issuing and recovering the loan atomically within a single block. That is precisely what makes flash loan-enabled attacks so structurally difficult to prevent at the lending layer. The vulnerability was entirely on Allbridge's side: specifically in how its stablecoin pools calculated and responded to sudden, extreme liquidity shifts. Robust pool designs typically incorporate safeguards such as time-weighted average prices, circuit breakers on abnormal volume spikes, or caps on single-block imbalances. Whether Allbridge's Core Bridge lacked any of these protections — or whether the attacker found a gap in their implementation — will be central to any post-mortem.
The $1.65 million figure places this exploit in the mid-tier of decentralized finance security incidents by dollar value, but the architectural lessons are disproportionately significant. Cross-chain bridges collectively have lost billions of dollars to exploits over the past several years. The Solana-to-Ethereum corridor, specifically, has become a high-value target as stablecoin volume on Solana has grown substantially. Attackers follow liquidity, and the maturation of Solana's decentralized finance ecosystem means its bridges now carry enough value to justify sophisticated, capital-intensive attack strategies — including flash loan maneuvers that require seven-figure upfront borrowing capacity.
For the broader infrastructure community, the pattern here is familiar but no less urgent: a flash loan inflates temporary capital, pool pricing logic is gamed, funds exit via the bridge, and a halt arrives after the damage is done. Until bridge protocols implement more adversarial stress-testing at the pool-pricing layer — and integrate real-time anomaly detection that can pause contracts automatically before a transaction finalizes — these post-exploit pauses will keep arriving too late. Allbridge now has the difficult work of rebuilding trust, auditing its remaining infrastructure, and determining whether affected users will be made whole.
Written by the editorial team — independent journalism powered by Bitcoin News.