Allbridge Core lost $1.65 million on Sunday to a flash-loan attack that manipulated the ratio between two stablecoins inside its own liquidity pools — the same class of exploit that took roughly $570,000 from the protocol in April 2023. The more useful signal for institutional desks is not the headline number but where it sits in this year’s loss distribution. CertiK counted 204 code-related incidents in the first half of 2026 totalling $151.6 million, an average of about $743,000 per event, against $444 million lost to wallet compromises at roughly $13 million each. Cheap, frequent, repeat-vector attacks are the category the industry has been slowest to close, and Allbridge is now a two-time entry in it.
The mechanics were unglamorous. The attacker borrowed $1.12 million in USD Coin (USDC) from Kamino, the Solana lending protocol, then pushed a rapid sequence of USDC/Tether (USDT) swaps through Allbridge Core’s pools to skew the ratio between the two assets. Because Allbridge Core prices liquidity withdrawals off that ratio, the distortion allowed the attacker to redeem liquidity at manipulated rates, repay the flash loan inside the same transaction, and keep the difference. Blockchain analytics account Onchain Lens traced the proceeds from Solana to Ethereum, where they were converted into Ether (ETH) and partially routed through privacy pools to frustrate tracking, according to Cointelegraph.
Allbridge halted the protocol within hours. “Allbridge Core is experiencing a security incident. We have paused the protocol as a precaution while we investigate. If you have liquidity in affected pools, please withdraw now,” the team said in a public statement. It followed with an unusual appeal to the traders who profited from the resulting price dislocation rather than the attacker: “The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage of it, please consider returning funds — this will go directly toward compensating affected LPs.” The awkward detail is that after the 2023 incident on BNB Chain, Allbridge relaunched with a “Rebalancer Authority” designed to correct exactly the kind of pool imbalance that has now been weaponised a second time.
That gap between audited controls and live outcomes is the theme security researchers keep returning to this year. “A protocol can pass a flawless code audit and still lose millions because of a compromised admin key,” Ronghui Gu, co-founder and chief executive at CertiK, told Forbes, describing a first half in which $1.32 billion was lost across 344 incidents. Gu’s point cuts both ways here: Allbridge was not undone by a stolen key but by design logic that survived a rewrite, which is the harder failure to remediate because there is no credential to rotate.
For infrastructure providers the relevant context is frequency, not severity. This is at least the sixth attack on a cross-chain bridge since May, and it lands in a year when DeFi hack counts hit a record while aggregate losses fell — Immunefi put first-half losses at $972 million across 207 incidents, down sharply from the 2022 peak. Bridges remain the structural chokepoint: they concentrate stablecoin liquidity, they price redemptions off internal state that a well-capitalised trader can move within one block, and they are the component institutional custodians can least easily route around when moving Total Value Locked (TVL) between chains.
The contrast with larger 2026 incidents is instructive. When an attacker spent $4.4 million to drain $20 million from the BonkDAO treasury in July, the vector was governance capture — expensive to execute, hard to repeat. A $1.12 million flash loan costs the attacker a gas fee and a few seconds. That asymmetry is why the long tail of sub-$2 million exploits keeps growing even as the industry gets better at preventing nine-figure catastrophes, and why desks allocating into curated institutional DeFi vaults increasingly underwrite bridge risk separately from protocol risk.
What to watch next is whether Allbridge restores the protocol with a redesigned pricing mechanism rather than another authority layer, and whether the funds routed into privacy pools surface at a centralised venue. Solana’s infrastructure is scaling quickly — the network is targeting 100-millisecond finality — but faster settlement compresses the window in which a manipulated pool can be detected and paused, not the window in which it can be drained. Until bridge pricing stops deriving from manipulable internal ratios, the sixth attack since May will not be the last.
This article is informational analysis only and is not financial, investment, or trading advice. Cryptocurrencies are highly volatile and can lose substantial value rapidly. Past performance and historical patterns do not guarantee future results. Do your own research and consult a regulated financial adviser before making any investment decision.