Allbridge Hack

TOTAL LOST $1.6M
Medium Flash Loan Attack

Summarize with AI

Affected Chain 2026 Incident surface
Recovered - No recovery reported
All-Time Rank #717 By amount stolen
Protocol Type Exploit/Flash Loan Attack Target category

Incident Overview

On July 20, 2026, the cross-chain bridging protocol Allbridge Core suffered a security exploit on its Solana deployment. The attacker extracted approximately $1.65 million in digital assets by manipulating the internal virtual balance accounting of its stable swap pool, forcing an immediate protocol pause.

The exploit targeted a flaw in how Allbridge Core tracks and calculates internal token valuations based on virtual pool balances. The attacker initiated the attack by securing a $1.12 million USDC flash loan from the Solana lending protocol Kamino. Using these funds, the attacker executed five consecutive USDT-to-USDT swaps. These specific transactions were designed to intentionally break and manipulate the internal virtual accounting mechanisms that dictate the asset exchange rates within the pool.

With the internal math severely skewed, the protocol vastly overvalued USDT relative to USDC. The attacker then executed a final swap, exchanging a mere 3,987 USDT to withdraw an outsized 2.24 million USDC from the drained liquidity pool. After accounting for the flash loan repayment and minor slippage, the exploiter walked away with a net profit of ~$1.65 million. The stolen assets were immediately bridged from Solana to a designated Ethereum address. The massive drainage left the pool severely imbalanced, creating a brief, highly visible positive arbitrage window for external bots and users before the Allbridge team officially paused the protocol and urged liquidity providers to withdraw their assets.

Solana Exploit Transaction: 3LNLaGi36bqoSBFBqcQ3ZvDbnGCxrxu4rqahZrnfHZjKSYxfR1mqiCXtBXjjeBmoRQDeSiKxZ7c1nFb8pBgTY39Q

Intermediary Ethereum Wallet: 0x651591b6…81ffDe

Incident Report

Protocol / Project Allbridge
Date of Incident
Attack Technique Flash Loan Attack
Classification Bridge

Protocol Information

Protocol Type Exploit/Flash Loan Attack
Official Website allbridge.io/
Protocol Twitter/X @Allbridge_io
Team Anonymous
Source Code Unverified

Market Context at Time of Hack

Token Categories
Ethereum Ecosystem HECO Ecosystem Avalanche Ecosystem Solana Ecosystem Polygon Ecosystem Fantom Ecosystem Terra Ecosystem Near Protocol Ecosystem

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of flash loan attack and Solidity and EVM internals
Capital Required Flash loan capital (borrowed atomically, zero upfront cost)
On-Chain Access Ability to interact with smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in Allbridge's contract logic - root cause: bridge
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Yes — skilled auditors routinely flag Flash Loan Attack vulnerabilities in code review

If you're auditing a protocol with similar architecture to Allbridge, these are the critical security checks that could have prevented this incident (July 2026).

  • Verify all logic paths related to Flash Loan Attack are guarded by proper access controls and input validation
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Sources & References

Learn to Prevent the Next Allbridge

The Allbridge hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial