Allbridge Core has paused operations following an exploit on Solana that drained roughly $1.66 million from the protocol’s liquidity swimming pools in a single transaction at round 17:51 UTC on July 19, in line with a brand new announcement from the mission.
The incident is notable not solely due to the scale of the loss, but additionally as a result of Allbridge Core handles important utilization, with over 890,000 wallets and a TVL of over $24 million in line with figures on its homepage. This incident additionally reopens questions concerning the security of liquidity pool-based bridge fashions.
Allbridge Core pauses after Solana exploit
Instantly upon detecting the incident, Allbridge paused Core whereas investigating, noting that it took the group about 25 minutes to establish and start shutting down the affected features. The incident occurred on Solana and was confirmed by the mission in a newly launched technical autopsy.
Allbridge Core is experiencing a safety incident. We have now paused the protocol as a precaution whereas we examine.
You probably have liquidity in affected swimming pools, please withdraw now.
The ensuing pool imbalance created a short lived constructive arbitrage window. When you took benefit… pic.twitter.com/Ovg7yT35SM
— Allbridge (@Allbridge_io) July 19, 2026
Allbridge acknowledged that the injury was contained to the 2 related swimming pools, whereas non-public keys and consumer wallets weren’t compromised. Within the preliminary section of dealing with the difficulty, the mission shifted its focus to limiting the unfold reasonably than permitting the protocol to proceed working usually whereas the pool state was distorted.
Pool-based swap design uncovered a weak point
In line with Allbridge’s technical documentation, Core makes use of a stablecoin liquidity pool mannequin with a digital steadiness to take care of inner valuation pegs. This design permits the bridge to function with out wrapped property, but it surely additionally leaves the system closely depending on how the pool handles the discrepancy between precise and recorded balances.
In line with the mission, the vulnerability emerged when same-asset swaps have been executed consecutively in the identical pool. Every subsequent swap pushed the interior state additional away from the precise liquidity, and when a flash mortgage was used as leverage, this deviation was giant sufficient for the attacker to extract worth earlier than the rebalancing mechanism may react.
This incident reveals that the difficulty lies within the pool-based swap logic when exploited in a concentrated sequence of transactions, reasonably than in Solana as an unbiased infrastructure.
About $1.66 million was drained from liquidity swimming pools
In line with the autopsy, the exploit occurred at round 17:51 UTC on July 19, and the whole worth drained from liquidity swimming pools was roughly $1.66 million, together with about 1,118,239 USDC and 538,692 USDT. Based mostly on the mission’s description, the attacker initiated the assault with a flash mortgage of round 1.12 million USDC from Kamino, then executed a collection of swaps to distort the pool ratio earlier than withdrawing liquidity on the skewed worth.
9-step exploit stream. Supply: Allbridge
The cash stream didn’t cease on Solana after that. In line with Allbridge and forensic companions, they traced roughly $1.63 million, with a portion bridged to Ethereum after which passing by channels comparable to Railgun, NEAR Intents, and Zcash Orchard. Dispersing by a number of layers like this makes the monitoring and restoration course of considerably extra complicated.
Allbridge strikes to comprise the injury
Allbridge prioritized locking the affected elements earlier than reopening routes that don’t depend on liquidity swimming pools. In line with the autopsy, the bridge has now resumed on these routes, whereas pool-based swaps stay disabled as a security measure. The mission can also be holding the liquidity pool web page open so LPs can withdraw their funds, whereas recommending they withdraw liquidity early because the swimming pools now not generate yields as earlier than.
Allbridge acknowledged that consumer liquidity exterior the affected swimming pools is just not straight threatened. The mission additionally subsequently known as on anybody who took benefit of the non permanent worth discrepancy after the incident to think about returning these earnings to assist compensate affected LPs.
The incident quickens a shift to a brand new structure
Allbridge acknowledged that Core and Allbridge Traditional will stop working of their present kind inside three months, whereas the brand new model of Core will utterly take away liquidity swimming pools and swap to routing by way of CCTP and LayerZero to cut back pool imbalance dangers. This can be a step in the suitable path for Allbridge Subsequent, the place the mission goals to prioritize appropriate routing as an alternative of concentrating all transaction flows into the identical mechanism.
With the present utilization scale of Allbridge Core, this transformation reveals that the exploit goes past a mere technical incident. It’s driving the mission towards a special structure whereas demonstrating that the pool-based bridge mannequin has turn out to be some extent that wants alternative reasonably than simply restore.










