BlockBriefe
Altcoins

Allbridge Core Halts After $1.65 Million Flash‑Loan Attack

Emma Whitfield 20.07.2026

How the Flash Loan Bypassed Allbridge’s Safeguards

The cross‑chain bridge Allbridge Core suffered a flash‑loan exploit that drained roughly $1.65 million. Security firms PeckShield and CertiK flagged the breach, prompting the bridge’s developers to pause operations on Tuesday for a thorough investigation. The incident was first identified by blockchain analytics firm Onchain Lens, which traced the attacker’s movements across Solana and other networks.

The exploit began with a $1.12 million flash loan taken from Kamino, a Solana‑based liquidity protocol. The borrower used the loan to manipulate Allbridge’s price oracle, inflating the value of a wrapped token. Once the artificial price was in place, the attacker swapped the over‑valued tokens for native assets, effectively siphoning the funds. PeckShield’s analysis highlighted the speed of the transaction, noting that the entire sequence unfolded within a single block. CertiK added that the bridge’s smart‑contract code lacked sufficient checks against rapid price swings, making it vulnerable to such attacks.

Onchain Lens detailed the attack’s mechanics, showing that the flash loan allowed the hacker to borrow massive capital without collateral. By feeding false price data into Allbridge’s oracle, the attacker created a temporary arbitrage window. The bridge’s contract then accepted the inflated token as legitimate collateral, releasing the underlying assets. Security researchers said the lack of a time‑weighted average price (TWAP) mechanism was a critical oversight. „A single‑block price feed is inherently risky,” one analyst wrote, emphasizing the need for multi‑block validation.

Could Similar Bridges Face the Same Threat?

The breach raises concerns for other cross‑chain bridges that rely on real‑time price feeds. Many protocols use similar oracle designs, which could be exploited by flash‑loan actors. Experts suggest that incorporating delay mechanisms, broader liquidity pools, and stricter loan caps can reduce exposure. „Bridges must assume that flash loans can be massive and instantaneous,” warned a CertiK spokesperson, urging developers to reassess their risk models. The Allbridge team has pledged to audit its contracts and introduce additional safeguards before resuming service.

The pause of Allbridge Core signals a cautious approach, but the incident may erode user confidence in decentralized bridges. Investors and developers are likely to demand more rigorous security audits and transparent post‑mortem reports. As the blockchain ecosystem matures, the balance between speed and safety will become a central theme in protocol design.

Frequently Asked Questions

What amount was stolen in the Allbridge exploit? Approximately $1.65 million was taken, with $1.12 million originating from a flash loan on the Kamino protocol.

Why did Allbridge halt its operations? The bridge’s developers paused the protocol to investigate the breach, assess vulnerabilities, and prevent further losses while they implement security upgrades.

How can users protect themselves from similar attacks? Users should diversify across multiple bridges, stay informed about security audits, and avoid depositing large sums into newly launched or untested cross‑chain services.

Share:

More stories: