Cross-chain protocol Allbridge halts after $1.65 million flash loan exploit

The cross-chain protocol Allbridge has paused operations following a $1.65 million flash loan exploit. The attacker manipulated liquidity pool ratios to withdraw assets, prompting the platform to request the return of funds from arbitrageurs.
Why it matters
This incident highlights the ongoing security vulnerabilities in decentralized finance (DeFi) protocols and the risks associated with flash loan attacks.
Allbridge is a bridge that lets users move assets between blockchains that do not communicate directly. Its Core product uses liquidity pools to transfer native stablecoins such as USDC and USDT without issuing wrapped versions of the assets.
The attacker used a $1.12 million flash loan from Solana lending protocol Kamino to rapidly swap USDC and USDT, manipulating the pools’ internal ratios before withdrawing assets at favorable rates, according to Onchain Lens. A flash loan is a loan taken and repaid within the same transaction.
The stolen assets were bridged to an Ethereum address and dispersed across additional addresses. It isn’t currently clear how much remains under the attacker’s control.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in