T
iTokenly

Allbridge Core hack — July 2026

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJuly 19, 2026
Target typeCross-chain bridge
Loss$1,650,000Price at time of incident
MethodFlash loan attackAn attacker borrowed roughly $1.12 million in USDC from the Solana lending protocol Kamino and swapped rapidly between USDC and USDT inside Allbridge Core's Solana pools. Because the pools price against internal reserves rather than external market rates, the swaps pushed the internal ratio far from the true one-to-one value of the two stablecoins, letting the attacker withdraw liquidity at the distorted rate and repay the flash loan in the same transaction.
ChainsSolana, Ethereum
OutcomeUnresolved

What happened

Allbridge Core, the pooled-liquidity cross-chain transfer product operated by Allbridge, lost about $1.65 million on 19 July 2026 when an attacker manipulated the ratio of its Solana stablecoin pools using flash-loaned capital.

The attacker borrowed roughly $1.12 million in USDC from Kamino, a Solana lending protocol, and used it to swap rapidly between USDC and USDT inside Allbridge Core. Because those pools price against each other on internal reserves rather than external market rates, the swaps drove the internal ratio far away from the real one-to-one value of the two stablecoins. The attacker then withdrew liquidity at the distorted rate and repaid Kamino within the same transaction. PeckShield and CertiK subsequently tracked the proceeds being bridged from Solana to Ethereum and routed through privacy protocols.

Allbridge paused the protocol and told liquidity providers in affected pools to withdraw immediately. It confirmed the $1.65 million figure itself, and all reporting on the incident uses that number. The imbalance left behind also opened an arbitrage window, and Allbridge asked anyone who profited from it to send those gains to a recovery address to help compensate affected liquidity providers, saying its goal was to return all affected funds.

Allbridge had been hit by a comparable flash-loan pool manipulation on BNB Chain in April 2023, a smaller incident from which it recovered most of the funds and after which it said it had changed its withdrawal mechanics. Following the Solana exploit it said Core would be rebuilt without liquidity pools, routing through CCTP and LayerZero instead, and that Core and Allbridge Classic would cease operating in their present form. No funds have been recovered.

Sources

  1. The BlockSecondary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. crypto.newsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Allbridge Core hack — July 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/allbridge-core
https://itokenly.com/hacks/allbridge-core

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.