Article Content
- •Allbridge Core paused operations after a $1.65 million exploit on July 20, 2026.
- •The attacker used a $1.12 million flash loan to manipulate liquidity pool ratios.
- •This incident is the sixth attack on cross-chain bridges since May 2026.
Allbridge Core paused its cross-chain bridge protocol on July 20, 2026, following a security incident that drained approximately $1.65 million from its Solana liquidity pools. The attacker utilized a $1.12 million flash loan from Kamino, manipulating stablecoin ratios through rapid swaps before withdrawing assets at distorted rates. The stolen funds were subsequently bridged to Ethereum and dispersed across multiple wallets. Allbridge urged users with liquidity in affected pools to withdraw their funds immediately and requested that those who profited from the temporary arbitrage return the funds to compensate affected liquidity providers. This incident marks the sixth attack on cross-chain bridges since May 2026, highlighting their vulnerability. Allbridge had previously faced a similar flash loan attack in April 2023, resulting in a loss of $573,000. The current exploit raises concerns about the security of cross-chain protocols and their susceptibility to manipulation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Allbridge in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…