- Andrey Velikiy commented on the $1.65 million Allbridge Core hack at Incrypted’s request.
- He spoke about the bridge’s current status, compensation, and the progress of the investigation.
- Velikiy also shared his view on liquidity pools, noting that their time is coming to an end.
- In his words, they are a “tasty target” for hackers.
Andrey Velikiy, co-founder of the Allbridge cross-chain protocol, told Incrypted in a comment about the $1.65 million hack, compensation for affected users, and the protocol’s future.
What Is This Project, and What Hack Are We Talking About?
Allbridge is a cross-chain protocol for transferring crypto assets between different networks. The Classic version uses wrapped tokens for this, while Core uses liquidity pools. The latter is specialized in transferring dollar stablecoins.
In an interview with Incrypted, Velikiy described how Allbridge Core works as follows:
“Users themselves deposit funds into liquidity pools. When the protocol uses these assets, they receive 80% of our fees, and the remaining 20% goes to the project. Where did the money that was later stolen come from? These are the assets that were deposited over the years, because their owners believed they were earning a solid return from turnover.”
On the morning of July 20, 2026, reports emerged that the Allbridge Core bridge had been hacked. The attacker used a flash loan via the Kamino protocol on the Solana network to manipulate the rate in the USDC/USDT pool, allowing them to withdraw more crypto assets than they should have.
The situation was further worsened by the fact that some other users took advantage of the opportunity for arbitrage. In the wake of the incident, Allbridge Core temporarily suspended operations, and the project’s total value locked (TVL) fell by more than 40%.
“The vulnerability was on Solana. Yes, specifically in the USDC/USDT pool. The attacker took a flash loan, tricked the pool’s math, and pulled out more money than they should have. But the bridge works in a way that it tries to balance all pools against each other. Because of that, and because people took advantage of the arbitrage opportunity, essentially all pools were affected. We stopped the bridge 30 minutes after the vulnerability was discovered, but by that point users had already ‘spread’ the losses across all networks,” Velikiy emphasized.
According to the project’s co-founder, the $1.65 million in damage is the amount the attacker stole. The team is still calculating the total losses, which also include arbitrage by some users.
“Some of the hacker’s funds went into the Railgun privacy protocol. We managed to stop them, they returned to an EVM address, and they are still sitting there as of this morning. Another part, and we are fairly confident about this, went into a shielded pool on Zcash,” Velikiy noted.
He said the team is trying to find a way to trace these assets, but it cannot be done while they are in the pool.
Current Status of the Bridge, Arbitrage, and Compensation
“We have the option to send funds not through liquidity pools, but via Circle’s CCTP protocol. When we resumed the bridge yesterday, we did it through that solution and LayerZero, without enabling the pools. Right now it’s operating at, roughly speaking, half capacity,” Velikiy commented.
He said the team currently has no clear understanding of how to return to the old operating mechanism, when users could use both pools and other infrastructure.
“To restart the pools, we basically need to settle everything, recreate them, and convince people to come back. Right now, immediately after the hack, that task seems impossible. We don’t have a button to restore everything to how it was. To get going, we have to rebuild everything anyway. For now, we think this solution — the bridge operating without pools, with people coming back and volumes recovering — works,” he added.
Velikiy believes liquidity pools themselves are a “juicy target” for hackers. This is especially important now that AI models have made significant progress in finding and exploiting vulnerabilities.
As an example, he cited Anthropic’s Fable 5. More details:
“Overall, we were planning to move to a new architecture. That is, for the bridge version we call Next, we originally built it without liquidity pools at all. So now, with the hack on top of that, I’m internally even more inclined not to go back to that architecture at all, because it’s a kind of constant magnet for hackers,” Velikiy said.
Notably, Allbridge Next is a universal cross-chain transfer solution that lets you combine pools and routing to work with both EVM and non-EVM networks. It was launched in 2026.
Velykyi also explained the move away from liquidity pools by saying that using them is less beneficial for end users, since fees are higher in that case.
Velykyi himself supports moving away from liquidity pools. However, before that, the team needs to fully close the “hole” that has formed, he added.
Notably, earlier the Allbridge team urged users who profited from arbitrage to return the funds, which would be used to compensate losses. However, according to Velykyi, the initiative was unsuccessful.
“People believe they earned it in good faith and are not willing to share. Unfortunately. […] Yesterday I checked the wallet, and it had zero transactions,” he noted.
As for compensation, the ideal option would be to recover the stolen crypto assets, Velykyi said. However, the team is also considering other options, including covering losses using protocol fees. But for that to work, users need to come back, he stressed.
Hacker Hunt
According to Velykyi, in the days since the hack, the team has not been sitting idle. The company is working with compliance and cybersecurity specialists at AMLBot and Global Ledger, and Crystal experts are also involved in the investigation, he emphasized.
The key difference between this hack and the 2023 incident is the hacker’s level of preparation. According to Velykyi, the attacker carefully thought through the plan, took the necessary steps to cover their tracks, and fully understood what to do and how to do it.
“It would have been easier for us to reach an agreement with the hacker, pretend it was a white hat, and pay a bounty like last time. Back then there were two hackers, and we managed to strike a deal with one of them for 10% of what was stolen. In return, there was no legal action from us,” he said.
However, according to Velykyi, last time specialists managed to identify the hacker’s jurisdiction and get in touch with them, which made negotiations easier. Now that option is not available, at least for now.
In closing, Velykyi noted that the team will provide details about what happened after the investigation produces some results.
Сообщение Allbridge Co-founder Commented on the Hack and Spoke About the Project’s Future появились сначала на INCRYPTED.




