Crypto

Allbridge Core halted after $1.65M Solana exploit



Allbridge Core has paused its cross-chain stablecoin protocol after a security incident on Solana that PeckShield estimated at about $1.65 million. 

Summary

  • Allbridge paused Core after a Solana exploit drained about $1.65 million, according to PeckShield estimates.
  • The attacker used a $1.12 million USDC flash loan to quickly distort stablecoin pool rates.
  • Allbridge urged liquidity providers to withdraw while investigators traced funds moved from Solana to Ethereum.

The protocol told users with funds in affected liquidity pools to withdraw while its team investigates. PeckShield also said the attacker moved the stolen assets from Solana to Ethereum.

The incident appears to involve manipulation of Allbridge Core’s USDC/USDT liquidity pool. Onchain Lens said the attacker used a $1.12 million USDC flash loan from Kamino, changed the pool balance through rapid swaps and withdrew liquidity at distorted rates. The exact loss figure remains under review, with Onchain Lens describing more than $1.1 million extracted and PeckShield estimating the broader exploit at about $1.65 million.

Allbridge pauses Core and warns liquidity providers

“Allbridge Core is experiencing a security incident,” the team said in its public notice. It added that the protocol had been paused as a precaution while the investigation continued. The project also issued a direct warning: “If you have liquidity in affected pools, please withdraw now.”

Allbridge said the attack left some pools temporarily out of balance. That imbalance created an arbitrage window that allowed some traders to profit from unusual pricing. The team asked anyone who benefited to consider returning funds to a recovery address. It said returned assets would go toward compensating affected liquidity providers. At the time of writing, the notice did not give a reopening date or publish a technical report.

In addition, according to Onchain Lens, the attacker borrowed $1.12 million in USDC through a flash loan from Kamino. The attacker then carried out rapid USDC and USDT swaps that changed the ratio inside the Allbridge stablecoin pool. After the pool price moved, the attacker withdrew liquidity using the distorted rate and repaid the flash loan within the same transaction.

Flash loans allow users to borrow and repay funds in one blockchain transaction without posting normal collateral. In this case, the loan itself was not described as the vulnerability. Instead, the borrowed liquidity allegedly gave the attacker enough capital to move the pool ratio and extract value before the transaction ended. PeckShield later said the stolen funds were bridged from Solana to Ethereum.

Allbridge faces another bridge security incident

The latest Allbridge Core exploit follows an earlier attack against the project. As crypto.news previously reported, Allbridge suffered a separate exploit in April 2023 after an attacker manipulated the swap price of a BNB Chain pool. The loss was estimated at about $573,000, and the project later recovered roughly $465,000 after offering the attacker a white-hat reward.

The new incident also comes during another active period for cross-chain security breaches. In May,the Verus-Ethereum bridge lost more than $11.5 million in an attack linked by researchers to missing validation checks. A separate crypto.news report said Transit Finance lost about $1.88 million in another cross-chain protocol exploit. Allbridge has not said whether the Solana incident shares technical similarities with those attacks.





Source link

What's your reaction?

Excited
0
Happy
0
In Love
0
Not Sure
0
Silly
0

You may also like

More in:Crypto

Leave a reply

Your email address will not be published. Required fields are marked *