Allbridge Core has reportedly been exploited again and the details highlight a recurring problem that continues to plague cross-chain infrastructure. Early estimates place the loss between ~$1.1M and ~$1.65M, with security firms and on-chain investigators still reconciling the final figure. What makes this incident particularly notable is that it does not appear to involve compromised keys, a smart contract takeover, or a traditional bridge vulnerability. Instead, the attacker reportedly used a flash loan of approximately $1.12M USDC from @Kamino, requiring no upfront capital. The borrowed funds were used to aggressively trade against @Allbridge_io’s Solana USDC/USDT liquidity pool, temporarily pushing the pool’s internal exchange rate away from fair market value. Once the pricing became distorted, liquidity was withdrawn at the manipulated rate, allowing the attacker to extract value before repaying the flash loan within the same atomic transaction. The entire operation was completed without leaving the attacker’s capital exposed. What’s difficult to ignore is the historical context. In 2023, @Allbridge_io suffered a similar exploit on @BNBCHAIN that resulted in roughly $650K in losses. At the time, the team stated that liquidity and withdrawal calculations had been updated to prevent a repeat incident. Yet the latest reports suggest that the @Solana deployment may have retained structural weaknesses that left stablecoin pools vulnerable to the same class of attack. This raises a broader question for the industry. Bridges continue to rank among crypto’s most frequently exploited systems, not necessarily because their code is always flawed, but because their architecture concentrates large pools of liquidity that secure cross-chain movement. When pricing mechanisms, liquidity accounting, or withdrawal logic can be manipulated, attackers are presented with an opportunity where a relatively small flaw can translate into a seven-figure payout. According to investigators, the stolen funds have already been bridged to @ethereum and are reportedly being routed through privacy-focused protocols, making recovery significantly more challenging. The most important takeaway isn’t the dollar amount lost. It’s that many of the industry’s largest exploits continue to emerge from known design risks rather than unknown vulnerabilities. Flash loans, liquidity manipulation, oracle assumptions, and pool accounting remain some of the most persistent attack vectors in DeFi. Until bridge architectures evolve beyond relying on massive liquidity pools with exploitable pricing mechanics, incidents like this may continue to be less of an exception and more of an expectation. Awaiting Allbridge’s official postmortem for confirmation of the final loss figure and a detailed explanation of exactly where the Solana pool design failed.
MR BLACKShare
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.