Stay connected with KayaToday, follow us on Instagram and Facebook for the latest news and reviews delivered straight to you.
Cross-chain bridges were supposed to be the connective tissue of a multi-chain crypto ecosystem, letting users move assets freely between blockchains like Solana, Ethereum, and BNB Chain. Instead, they have become the most reliably exploited infrastructure in decentralised finance. The latest victim is Allbridge Core, which lost approximately $1.65 million on Sunday after an attacker manipulated its stablecoin pool through a flash loan, making it at least the sixth bridge protocol targeted since May.
Allbridge, the company behind Allbridge Core, confirmed the breach in a post on X, saying it had paused the protocol as a precaution while investigating. It urged anyone with liquidity in affected pools to withdraw immediately.
How the Attacker Turned a Loan Into a Windfall
The mechanics of this exploit are worth understanding because they reveal something important about how flash loan attacks work and why stablecoin pools are particularly vulnerable to them.
According to Onchain Lens, the attacker began by taking a $1.12 million USDC flash loan from Kamino, a lending protocol on Solana. Flash loans are uncollateralised borrowings that must be repaid within a single transaction block, meaning the attacker needed no upfront capital to execute the attack. Using that borrowed capital, the attacker conducted rapid swaps between USDC and USDT inside Allbridge Core’s stablecoin pool. Because the pool’s exchange rate is calculated algorithmically based on the ratio of assets held within it, flooding one side with large, rapid trades distorted the rate significantly.
With the pool’s pricing now artificially skewed, the attacker withdrew liquidity at the manipulated rates, effectively extracting more value than they deposited. They then repaid the $1.12 million USDC loan and kept the difference. The stolen funds were bridged from Solana to Ethereum before being routed into privacy pools, complicating any recovery effort.
Allbridge Core acknowledged the pool imbalance in its post-incident statement and appealed to anyone who may have profited from the resulting arbitrage window to return the funds voluntarily, noting that any returned capital would go directly toward compensating affected liquidity providers.
This is not Allbridge Core’s first encounter with this class of attack. In April 2023, the protocol was exploited for $573,000 through a flash loan attack on its BNB Chain pool. In that incident, the attacker operated simultaneously as both a liquidity provider and a swapper, exploiting a flaw in the smart contract’s price calculation logic to drain $289,900 in Binance USD and $290,900 in USDT. The fact that a structurally similar attack succeeded again, on a different chain deployment, raises serious questions about how thoroughly the lessons of 2023 were applied across the protocol’s full infrastructure.
A Pattern That Is Becoming Impossible to Ignore
The Allbridge incident does not stand alone. It is the latest in a string of bridge exploits that have accelerated since May, and the list of affected protocols is growing quickly.
In June, Taiko, an Ethereum layer-2 blockchain, had to urge users to withdraw assets after attackers stole $1.7 million from one of its bridge protocols. Taiko eventually reopened its bridge 11 days later after completing a four-step recovery plan. Weeks before that, Secret Network was hit through an infinite mint bug in a vulnerable smart contract, which generated unbacked versions of Axelar-wrapped assets and resulted in a $4.67 million loss. The Gravity Bridge, Verus Bridge, and Butter Network have also been targeted in the same period.
The concentration of attacks on bridges is not coincidental. Bridges are structurally attractive targets because they hold large pools of assets that back bridged tokens on destination blockchains. Unlike a single-chain protocol where the attack surface is contained, a cross-chain bridge must maintain liquidity on multiple networks simultaneously, each with its own smart contract deployment and its own potential vulnerabilities. An attacker who finds a flaw in any one of those deployments can potentially drain the entire pool backing that chain’s assets.
Flash loan attacks compound this problem because they lower the barrier to entry dramatically. An attacker does not need significant capital to manipulate a pool. They only need to identify a pricing mechanism that can be distorted within a single transaction block, borrow enough to create that distortion, and execute the withdrawal before the loan comes due. The attack is essentially risk-free for the attacker if the exploit works, and costless if it does not.
Why This Matters for the Broader DeFi Ecosystem
For retail users and liquidity providers in Malaysia, Singapore, and across Southeast Asia who participate in DeFi through cross-chain protocols, this pattern carries a direct practical implication. Liquidity provision in bridge pools is often marketed as a relatively low-risk yield strategy compared to more volatile DeFi positions. The Allbridge incidents, taken together, challenge that framing. Liquidity providers in these pools bear concentrated smart contract risk, and that risk is not always adequately priced into the yields on offer.
The broader concern is structural. Cross-chain interoperability is a genuine technical need in a multi-chain environment, and bridges fill that need today because no better solution has achieved widespread adoption. But the frequency and consistency of these exploits suggest that the current generation of bridge architecture carries systemic weaknesses that incremental security patches have not resolved. Until bridge protocols can demonstrate sustained resilience across all their chain deployments, not just the ones that have already been attacked, the sector will continue to function as one of the most reliable sources of losses in decentralised finance.
Read More: Galaxy Digital’s Stadium Deal Is a Billboard for Crypto’s Texas Ambitions