Allbridge Hack
What happened
On July 20, 2026, the cross-chain bridging protocol Allbridge Core suffered a security exploit on its Solana deployment. The attacker extracted approximately $1.65 million in digital assets by manipulating the internal virtual balance accounting of its stable swap pool, forcing an immediate protocol pause.
The exploit targeted a flaw in how Allbridge Core tracks and calculates internal token valuations based on virtual pool balances. The attacker initiated the attack by securing a $1.12 million USDC flash loan from the Solana lending protocol Kamino. Using these funds, the attacker executed five consecutive USDT-to-USDT swaps. These specific transactions were designed to intentionally break and manipulate the internal virtual accounting mechanisms that dictate the asset exchange rates within the pool.
With the internal math severely skewed, the protocol vastly overvalued USDT relative to USDC. The attacker then executed a final swap, exchanging a mere 3,987 USDT to withdraw an outsized 2.24 million USDC from the drained liquidity pool. After accounting for the flash loan repayment and minor slippage, the exploiter walked away with a net profit of ~$1.65 million. The stolen assets were immediately bridged from Solana to a designated Ethereum address. The massive drainage left the pool severely imbalanced, creating a brief, highly visible positive arbitrage window for external bots and users before the Allbridge team officially paused the protocol and urged liquidity providers to withdraw their assets.
Solana Exploit Transaction: 3LNLaGi36b…gTY39Q
Intermediary Ethereum Wallet: 0x651591b68A9c9650FB23F642162353306281ffDe
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report Report x.com
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.