A cross-chain bridge protocol just became the latest casualty in DeFi’s ongoing security crisis. The Allbridge Solana exploit drained approximately $1.65 million from the protocol before the attacker vanished into Ethereum — and the incident is raising hard questions about whether liquidity pool infrastructure on Solana is ready for the stakes being placed on it.
Summary
Key takeaways
- Allbridge paused all operations after an attacker drained roughly $1.65 million from its Solana-based infrastructure.
- The exploit used a $1.12 million USDC flash loan from Kamino to manipulate the USDC/USDT liquidity pool.
- Stolen funds were bridged from Solana to Ethereum and converted into ETH, according to on-chain data flagged by Arkham Intelligence.
- Liquidity providers in affected pools are urged by Allbridge to withdraw their funds immediately.
- This is not Allbridge’s first exploit — a 2023 attack on its BNB Chain pools caused roughly $570,000 in losses, of which approximately $465,000 was later recovered through a white-hat arrangement.
Allbridge Halts Operations After the Solana Attack
Allbridge moved quickly to pause its operations once the exploit was confirmed. The protocol, which focuses on moving stablecoins across both EVM-compatible networks and non-EVM chains like Solana, found itself in damage-control mode as the scale of the theft became clear.
The protocol’s immediate public message was directed at users with exposure: liquidity providers in affected pools should withdraw their funds without delay. That advice carries weight. When a bridge protocol halts operations mid-exploit, the window to recover deposited assets can narrow fast.
On-chain data tracked by Arkham Intelligence confirmed the fund movement — the attacker extracted the assets from Allbridge’s infrastructure, bridged them from Solana to Ethereum, and converted the proceeds into ETH. The cross-chain nature of the exit makes recovery substantially more complicated than a single-chain incident.
How the Exploit Actually Worked
A Flash Loan as the Entry Point
The mechanics relied on a well-worn but still effective playbook. The attacker sourced a $1.12 million USDC flash loan from Kamino — a lending protocol on Solana — and used those borrowed funds to artificially distort conditions inside Allbridge’s USDC/USDT liquidity pool.
Flash loans are borrowed and repaid within a single transaction block, meaning the attacker needed no upfront capital of their own. The borrowed USDC became the lever to manipulate the pool’s pricing or balance mechanics, ultimately allowing the attacker to extract funds that exceeded what they legitimately deposited.
Bridging Out Through Ethereum
Once the pool manipulation was complete, the funds didn’t stay on Solana. The attacker used cross-chain bridging — the very functionality Allbridge is built to provide — to move the proceeds to Ethereum, where they were swapped into ETH.
That routing decision is significant. Moving assets to Ethereum and converting them into ETH adds layers of complexity to any recovery effort, since the trail crosses two separate blockchain ecosystems. Platforms like Arkham Intelligence are tracking the attacker’s wallet, and any movement toward centralized exchange deposit addresses could be an early indicator of whether a freeze or partial recovery is feasible.
This Isn’t Allbridge’s First Time
Context matters here. In April 2023, Allbridge suffered a flash-loan attack targeting its BNB Chain liquidity pools, resulting in roughly $570,000 in losses. That incident also involved price manipulation. Allbridge eventually recovered approximately $465,000 of those funds through a white-hat hacker arrangement — a relatively successful outcome by DeFi standards.
The 2026 incident is larger, spans two blockchain ecosystems, and involves a different chain entirely. Whether the team can replicate a similar recovery under these more complex conditions is the central question hanging over the protocol right now.
The broader DeFi bridge space has not been kind recently. In April 2026, Kelp DAO’s LayerZero-powered bridge lost $292 million in a single exploit — a stark reminder that cross-chain infrastructure remains one of the most targeted attack surfaces in the industry.
What This Means for Solana’s DeFi Ecosystem
The Allbridge Solana exploit lands at an awkward moment for the network’s DeFi ambitions. Solana has been attracting significant liquidity and developer activity, positioning itself as a high-throughput alternative for decentralized finance applications. But incidents like this expose a persistent vulnerability: smart contract security and liquidity pool design haven’t kept pace with the capital flowing in.
Flash loan attacks, in particular, reveal structural weaknesses in how pools handle sudden, massive liquidity imbalances. When a protocol can be manipulated using borrowed capital that never actually leaves the attacker’s control, the underlying pool mechanics become the target — not just the smart contract code. That’s a design challenge with no trivial solution, and it applies broadly across DeFi regardless of which chain is involved.
For liquidity providers, the practical implication is immediate: funds deposited in Allbridge’s affected pools carry elevated risk until the protocol resumes operations, completes a post-mortem, and implements verifiable security improvements. The urgency of Allbridge’s own withdrawal recommendation underscores that point.
From a market perspective, repeated bridge exploits tend to suppress institutional appetite for DeFi bridge exposure. Each incident reinforces the argument that cross-chain infrastructure is still in a maturation phase — technically capable of moving billions, but not yet consistently hardened against sophisticated attackers willing to probe pool mechanics at scale.
FAQ
What triggered Allbridge to pause its operations?
Allbridge paused operations after a $1.65 million exploit involving a USDC flash loan used to manipulate the USDC/USDT liquidity pool on Solana. The protocol halted activity as a precautionary measure while the incident was being assessed.
How was the exploit conducted?
The attacker used a $1.12 million USDC flash loan from Kamino to manipulate the USDC/USDT liquidity pool on Solana. After extracting the funds, they bridged the proceeds from Solana to Ethereum and converted them into ETH, according to on-chain data tracked by Arkham Intelligence.
What should liquidity providers do in response to the exploit?
Allbridge is urging liquidity providers with funds in the affected pools to withdraw their assets immediately to prevent further potential losses while the protocol remains paused.
What broader implications does this exploit have for Solana’s DeFi ecosystem?
The exploit exposes vulnerabilities in DeFi liquidity pool design and smart contract security on Solana, likely increasing scrutiny of bridge protocols, prompting investor caution, and reinforcing the case for more rigorous security audits across cross-chain infrastructure.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

