Allbridge Hack
Incident Overview
On July 20, 2026, the cross-chain bridging protocol Allbridge Core suffered a security exploit on its Solana deployment. The attacker extracted approximately $1.65 million in digital assets by manipulating the internal virtual balance accounting of its stable swap pool, forcing an immediate protocol pause.
The exploit targeted a flaw in how Allbridge Core tracks and calculates internal token valuations based on virtual pool balances. The attacker initiated the attack by securing a $1.12 million USDC flash loan from the Solana lending protocol Kamino. Using these funds, the attacker executed five consecutive USDT-to-USDT swaps. These specific transactions were designed to intentionally break and manipulate the internal virtual accounting mechanisms that dictate the asset exchange rates within the pool.
With the internal math severely skewed, the protocol vastly overvalued USDT relative to USDC. The attacker then executed a final swap, exchanging a mere 3,987 USDT to withdraw an outsized 2.24 million USDC from the drained liquidity pool. After accounting for the flash loan repayment and minor slippage, the exploiter walked away with a net profit of ~$1.65 million. The stolen assets were immediately bridged from Solana to a designated Ethereum address. The massive drainage left the pool severely imbalanced, creating a brief, highly visible positive arbitrage window for external bots and users before the Allbridge team officially paused the protocol and urged liquidity providers to withdraw their assets.
Solana Exploit Transaction: 3LNLaGi36bqoSBFBqcQ3ZvDbnGCxrxu4rqahZrnfHZjKSYxfR1mqiCXtBXjjeBmoRQDeSiKxZ7c1nFb8pBgTY39Q
Intermediary Ethereum Wallet: 0x651591b6…81ffDe
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Allbridge, these are the critical security checks that could have prevented this incident (July 2026).
- Verify all logic paths related to Flash Loan Attack are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Allbridge
The Allbridge hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.