Solana cryptocurrency tokens for a story about the Allbridge Core liquidity-pool exploit.

Allbridge Paused Its Bridge. One Pool Equation Explains Why

July 20, 2026 7:24 pm Comments

Allbridge Core is moving money again.

The version that came back is missing the feature that made Sunday’s $1.65 million attack possible.

No liquidity pools. No internal pool ratio for an attacker to bend.

Transfers now route through Circle’s Cross-Chain Transfer Protocol and LayerZero.

That is a fast architectural retreat, and a revealing one.

The attacker did not break Solana, guess a private key or forge a cross-chain message. The opening was inside the math Allbridge Core used to price swaps between stablecoins.

The Block reported that the attack began with a roughly $1.12 million flash loan from Kamino on Solana. The borrowed capital was used to swap USDC for USDT rapidly enough to distort the balance between Allbridge’s stablecoin pools.

Once that ratio moved, the protocol’s own pricing logic offered the attacker a favorable withdrawal rate. The funds were extracted, the flash loan was repaid inside the transaction sequence, and the remaining value left the system.

The exploit was complicated in execution. Its economic shape was brutally simple: borrow size, push the pool out of balance, withdraw at the temporary price, repay the loan.

Security firms estimated the loss at roughly $1.65 million and traced the proceeds across the bridge to Ethereum.

The pool was the price feed.

Automated market makers do not call a human dealer before every trade. They infer price from the assets sitting on each side of a pool and apply a formula that changes the quote as the balance changes.

That works because ordinary traders are small relative to the pool. A large trade should move the price against the trader, and arbitrageurs should pull the pool back toward the wider market.

Flash loans change the scale of the contest.

A flash loan lets a trader borrow a large amount without posting traditional collateral, provided the principal and fee are returned before the transaction finishes. If any step fails, the whole sequence reverts.

That makes flash loans useful for legitimate arbitrage and refinancing. It also lets an attacker rent enormous buying power for a few seconds and aim it at a protocol that treats its own pool balance as truth.

Allbridge acknowledged that the incident created a temporary positive-arbitrage window. The protocol initially asked users who benefited from that imbalance to return funds so affected liquidity providers could be compensated.

The wording matters. Some wallets may have interacted with a broken price after the first malicious trade without being the original attacker.

The final accounting will have to separate intentional exploitation from bots executing whatever arbitrage the chain presented.

CertiK’s onchain review traced roughly $1.65 million from the Solana incident to an Ethereum address before the assets were dispersed further. Other investigators reported that the proceeds moved through privacy tools after crossing chains.

Moving the money does not erase the trail. It does make recovery slower, especially once funds are split across assets, networks and services with different compliance policies.

Allbridge did not wait for the postmortem.

The team paused Core on Sunday and told liquidity providers in affected pools to withdraw. By Monday, it said Core was back online using CCTP and LayerZero for transfers, with the liquidity pools removed.

Allbridge Core was built to move native stablecoins between EVM and non-EVM networks, including chains whose transaction systems do not naturally communicate. Its pools supplied liquidity on each chain so users could send one native stablecoin and receive another without relying on a wrapped representation or a centralized exchange account.

That convenience carried inventory risk. A bridge with pools has to keep enough assets on both sides, price conversions and manage imbalances.

The same machinery that makes a cross-chain swap feel immediate creates something an attacker can manipulate.

CCTP takes a different route for supported Circle assets. USDC is burned on the source chain and minted on the destination after Circle’s attestation service verifies the burn.

Liquidity does not have to sit in an Allbridge pool waiting for the next transfer.

LayerZero supplies messaging infrastructure that can route other transfers without recreating the exact pool model Allbridge just abandoned.

The relaunch therefore preserves cross-chain movement while moving the swap inventory and pricing risk outside the compromised design.

The tradeoff is real. A pool-free bridge depends more heavily on outside transport and token-issuer infrastructure.

Its asset and route coverage may differ from a bridge willing to warehouse liquidity everywhere.

But the attack surface changes. There is no Allbridge USDC-to-USDT pool balance to manipulate if there is no Allbridge pool.

The company says Allbridge Next continued operating normally during the incident. It also accelerated an existing migration plan: Core and Classic are expected to stop operating in their current forms within three months, and liquidity providers have been told to withdraw ahead of the transition.

That turns Sunday’s exploit into more than another line in DeFi’s loss ledger.

Allbridge has chosen to remove an entire category of risk instead of promising a better version of the same equation.

Security fixes rarely arrive that cleanly. Most protocols patch a check, change a limit and keep the architecture intact.

Here, the pool was the product—and the pool was the problem.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.