Allbridge Core just lost $1.65 million to the exact kind of flash loan attack that hit it three years ago.
On July 19, an attacker used a $1.12 million USDC flash loan from the Solana lending protocol Kamino to drain Allbridge Core's stablecoin pools. PeckShield put the total loss at roughly $1.65 million. Fast. The funds were bridged from Solana to Ethereum within hours, according to the security firm's alert, and later routed toward privacy pools. Allbridge paused the protocol and told liquidity providers to withdraw what they could.
You don't need to know much about DeFi mechanics to see the problem here. Allbridge prices liquidity withdrawals off the ratio between USDC and USDT sitting inside its own pools. The attacker borrowed a large flash loan, ran a burst of rapid USDC and USDT swaps to skew that ratio, then withdrew liquidity at the distorted rate and repaid the loan, all inside a single transaction. No one outside the blockchain ever had a chance to react. That's the nature of a flash loan: borrow, manipulate, profit, repay, before the next block even lands.
Here's the part that should worry anyone holding Allbridge's token or parking stablecoins in its pools. This is not a new attack. In April 2023, Allbridge Core was drained of about $570,000 through a nearly identical flash loan attack on its BNB Chain pools, where the attacker acted as both liquidity provider and swapper to manipulate swap prices. The team recovered roughly $465,000 of that through a white-hat negotiation, paused the protocol, and relaunched with new defenses, including a Rebalancer Authority designed to correct exactly the kind of pool imbalance that just got exploited again, and an automatic shutdown for extreme imbalances. Those defenses did not stop this attack.
A Bounty, Not a Bailout
That's the real question, and Allbridge hasn't answered it yet. The team's public response so far has been a request, not an explanation: a Medium post asking anyone who profited from the arbitrage window the exploit created to send funds to a recovery address, with the proceeds going toward compensating affected liquidity providers. No fixed compensation figure. No timeline. Just an ask and a wallet address. That's a bounty, not a bailout. Whether LPs get made whole depends on how generous strangers feel, not on protocol reserves.
Compare that with what happened two days earlier, on July 17, when Across Protocol reported its first security incident since launching in 2021, after more than $34 billion in bridged volume with zero prior exploits. Across's architecture uses relayers who front capital to users immediately and get reimbursed later from the bridge's own liquidity. When the exploit hit, the loss landed on Risk Labs, the team behind Across. Not on user funds. Nobody needed a compensation plan because nobody's money was ever at risk in the first place. That's not luck. That's a design choice made years before the attack happened.
Allbridge's design choice was different: price internal state off a ratio that a single well-funded actor can move in one transaction. It worked in theory until it got tested twice, three years apart, by the same category of attacker doing the same thing.
A Pattern Across DeFi Bridges
DeFi bridges have had a brutal stretch. StartupFortune has covered Across's own Solana incident and Bonzo Finance's exploit in recent weeks, and Allbridge is now a distinct entry on that list, with its own on-chain trail and its own repeat offense. Twice, in fact. If you're allocating capital to a yield protocol for the APY alone, ask a narrower question first: what happens to your money the moment someone with a large enough flash loan decides to test the pricing model. Allbridge has now answered that question twice, and both times the answer was the same.
Also read: Pump.fun Survives Its Biggest Token Unlock and a Viral Raccoon Coin Takes Over • Kraken Launches Dollar Settled Bitcoin and Ether Options to Fix a Broken Market • US Regulators Missed Their Own Deadline to Finish Stablecoin Rules