Allbridge Core has paused operations following an exploit on Solana that drained roughly $1.66 million from the protocol’s liquidity swimming pools in a single transaction at round 17:51 UTC on July 19, in response to a brand new announcement from the undertaking.
The incident is notable not solely due to the dimensions of the loss, but in addition as a result of Allbridge Core handles vital utilization, with over 890,000 wallets and a TVL of over $24 million in response to figures on its homepage. This incident additionally reopens questions in regards to the security of liquidity pool-based bridge fashions.
Allbridge Core pauses after Solana exploit
Instantly upon detecting the incident, Allbridge paused Core whereas investigating, noting that it took the crew about 25 minutes to determine and start shutting down the affected features. The incident occurred on Solana and was confirmed by the undertaking in a newly launched technical autopsy.
Allbridge Core is experiencing a safety incident. We’ve paused the protocol as a precaution whereas we examine.
When you’ve got liquidity in affected swimming pools, please withdraw now.
The ensuing pool imbalance created a short lived optimistic arbitrage window. Should you took benefit… pic.twitter.com/Ovg7yT35SM
— Allbridge (@Allbridge_io) July 19, 2026
Allbridge said that the harm was contained to the 2 related swimming pools, whereas personal keys and person wallets weren’t compromised. Within the preliminary part of dealing with the problem, the undertaking shifted its focus to limiting the unfold slightly than permitting the protocol to proceed working usually whereas the pool state was distorted.
Pool-based swap design uncovered a weak point
In accordance with Allbridge’s technical documentation, Core makes use of a stablecoin liquidity pool mannequin with a digital stability to take care of inside valuation pegs. This design permits the bridge to function with out wrapped belongings, however it additionally leaves the system closely depending on how the pool handles the discrepancy between precise and recorded balances.
In accordance with the undertaking, the vulnerability emerged when same-asset swaps have been executed consecutively in the identical pool. Every subsequent swap pushed the inner state additional away from the precise liquidity, and when a flash mortgage was used as leverage, this deviation was massive sufficient for the attacker to extract worth earlier than the rebalancing mechanism might react.
This incident exhibits that the problem lies within the pool-based swap logic when exploited in a concentrated sequence of transactions, slightly than in Solana as an unbiased infrastructure.
About $1.66 million was drained from liquidity swimming pools
In accordance with the autopsy, the exploit occurred at round 17:51 UTC on July 19, and the full worth drained from liquidity swimming pools was roughly $1.66 million, together with about 1,118,239 USDC and 538,692 USDT. Primarily based on the undertaking’s description, the attacker initiated the assault with a flash mortgage of round 1.12 million USDC from Kamino, then executed a sequence of swaps to distort the pool ratio earlier than withdrawing liquidity on the skewed value.
9-step exploit move. Supply: Allbridge
The cash move didn’t cease on Solana after that. In accordance with Allbridge and forensic companions, they traced roughly $1.63 million, with a portion bridged to Ethereum after which passing via channels similar to Railgun, NEAR Intents, and Zcash Orchard. Dispersing via a number of layers like this makes the monitoring and restoration course of considerably extra advanced.
Allbridge strikes to include the harm
Allbridge prioritized locking the affected components earlier than reopening routes that don’t depend on liquidity swimming pools. In accordance with the autopsy, the bridge has now resumed on these routes, whereas pool-based swaps stay disabled as a security measure. The undertaking can also be retaining the liquidity pool web page open so LPs can withdraw their funds, whereas recommending they withdraw liquidity early because the swimming pools not generate yields as earlier than.
Allbridge said that person liquidity outdoors the affected swimming pools will not be immediately threatened. The undertaking additionally subsequently known as on anybody who took benefit of the non permanent value discrepancy after the incident to contemplate returning these earnings to assist compensate affected LPs.
The incident quickens a shift to a brand new structure
Allbridge said that Core and Allbridge Basic will stop working of their present type inside three months, whereas the brand new model of Core will fully take away liquidity swimming pools and swap to routing through CCTP and LayerZero to scale back pool imbalance dangers. This can be a step in the appropriate course for Allbridge Subsequent, the place the undertaking goals to prioritize appropriate routing as a substitute of concentrating all transaction flows into the identical mechanism.
With the present utilization scale of Allbridge Core, this alteration exhibits that the exploit goes past a mere technical incident. It’s driving the undertaking towards a unique structure whereas demonstrating that the pool-based bridge mannequin has develop into a degree that wants substitute slightly than simply restore.








