Allbridge Suspends Core Bridge Operations Following $1.65M Flash Loan Attack
$1.12 million borrowed. $1.65 million drained. Zero collateral at risk for the attacker. On July 20, Allbridge paused its Core bridge after a single transaction exploited Solana-side liquidity pools through a Kamino flash loan.

Flash Loan Vector: $1.12M Borrow, $1.65M Extraction
The mechanism: borrow a large stablecoin position, distort pool ratios within Allbridge's bridge pools, then withdraw at inflated rates. Classic oracle manipulation via temporary liquidity imbalance.
The attack surface here was not novel. Flash loan exploits against bridge liquidity pools follow a repeatable pattern — borrow, distort, extract, repay — all within one atomic transaction. The hardware overhead is zero. The capital requirement is temporary. The attacker's actual risk exposure ends the moment the transaction either succeeds or reverts.
Scope and Current State
Allbridge confirmed the pause of its Core bridge. The drain totaled roughly $1.65 million from Solana liquidity pools. No further specifics on which stablecoins were targeted or the exact pool composition have been disclosed in available reporting.
This is not an isolated event. CoinMarketCap reports cumulative DeFi losses exceeding $600 million over a three-week window, including the Kelp DAO bridge exploit. Yahoo Finance documents a separate $6 million vault exploit at Summer.fi that forced the platform into wind-down mode. The attack frequency is compressing. The per-exploit yield for attackers remains viable.
What This Means for Yield Positions
Three checkpoints for anyone holding bridge-derived or pool-based yield:
1. Pool composition audit. If your yield source involves cross-chain bridge pools, verify whether the protocol uses time-weighted average pricing or spot oracle pricing for swaps. Spot pricing is the attack vector. Protocols relying on instantaneous pool ratios without TWAP safeguards are exposed to the same distortion technique.
2. Flash loan exposure mapping. Determine if the protocol you deposit into has flash-loan-resistant pricing — specifically, whether large single-block borrow-and-repay cycles can move internal exchange rates. If the answer is unknown, treat the position as unaudited risk.
3. Pause protocol awareness. Allbridge halted operations post-exploit. If your capital sits in a bridge pool, a protocol pause means withdrawal freeze. Understand the emergency mechanisms before depositing, not after.
Verdict
The Allbridge exploit is a $1.65 million confirmation of a known attack class. No new math. No novel vector. The protocol used pool-ratio pricing that a flash loan could distort within a single transaction. Any yield protocol operating under similar mechanics — instant spot pricing, no TWAP, no borrow caps within a block — carries the same structural vulnerability.
Audit your exposure. If the pricing mechanism of your yield source cannot survive a $1.12 million single-block borrow, the risk-reward ratio on that position is mispriced.