Allbridge Core has paused operations following an exploit on Solana that drained roughly $1.66 million from the protocol’s liquidity swimming pools in a single transaction at round 17:51 UTC on July 19, based on a brand new announcement from the mission.
The incident is notable not solely due to the scale of the loss, but in addition as a result of Allbridge Core handles vital utilization, with over 890,000 wallets and a TVL of over $24 million based on figures on its homepage. This incident additionally reopens questions in regards to the security of liquidity pool-based bridge fashions.
Allbridge Core pauses after Solana exploit
Instantly upon detecting the incident, Allbridge paused Core whereas investigating, noting that it took the crew about 25 minutes to determine and start shutting down the affected features. The incident occurred on Solana and was confirmed by the mission in a newly launched technical autopsy.
Allbridge Core is experiencing a safety incident. We have now paused the protocol as a precaution whereas we examine.
When you’ve got liquidity in affected swimming pools, please withdraw now.
The ensuing pool imbalance created a short lived constructive arbitrage window. If you happen to took benefit… pic.twitter.com/Ovg7yT35SM
— Allbridge (@Allbridge_io) July 19, 2026
Allbridge acknowledged that the harm was contained to the 2 related swimming pools, whereas non-public keys and person wallets weren’t compromised. Within the preliminary part of dealing with the difficulty, the mission shifted its focus to limiting the unfold fairly than permitting the protocol to proceed working usually whereas the pool state was distorted.
Pool-based swap design uncovered a weak point
In response to Allbridge’s technical documentation, Core makes use of a stablecoin liquidity pool mannequin with a digital steadiness to take care of inner valuation pegs. This design permits the bridge to function with out wrapped property, but it surely additionally leaves the system closely depending on how the pool handles the discrepancy between precise and recorded balances.
In response to the mission, the vulnerability emerged when same-asset swaps had been executed consecutively in the identical pool. Every subsequent swap pushed the inner state additional away from the precise liquidity, and when a flash mortgage was used as leverage, this deviation was massive sufficient for the attacker to extract worth earlier than the rebalancing mechanism might react.
This incident exhibits that the difficulty lies within the pool-based swap logic when exploited in a concentrated sequence of transactions, fairly than in Solana as an unbiased infrastructure.
About $1.66 million was drained from liquidity swimming pools
In response to the autopsy, the exploit occurred at round 17:51 UTC on July 19, and the entire worth drained from liquidity swimming pools was roughly $1.66 million, together with about 1,118,239 USDC and 538,692 USDT. Primarily based on the mission’s description, the attacker initiated the assault with a flash mortgage of round 1.12 million USDC from Kamino, then executed a collection of swaps to distort the pool ratio earlier than withdrawing liquidity on the skewed value.
9-step exploit circulation. Supply: Allbridge
The cash circulation didn’t cease on Solana after that. In response to Allbridge and forensic companions, they traced roughly $1.63 million, with a portion bridged to Ethereum after which passing by channels reminiscent of Railgun, NEAR Intents, and Zcash Orchard. Dispersing by a number of layers like this makes the monitoring and restoration course of considerably extra complicated.
Allbridge strikes to include the harm
Allbridge prioritized locking the affected elements earlier than reopening routes that don’t depend on liquidity swimming pools. In response to the autopsy, the bridge has now resumed on these routes, whereas pool-based swaps stay disabled as a security measure. The mission can also be maintaining the liquidity pool web page open so LPs can withdraw their funds, whereas recommending they withdraw liquidity early because the swimming pools now not generate yields as earlier than.
Allbridge acknowledged that person liquidity outdoors the affected swimming pools just isn’t straight threatened. The mission additionally subsequently referred to as on anybody who took benefit of the momentary value discrepancy after the incident to contemplate returning these earnings to assist compensate affected LPs.
The incident accelerates a shift to a brand new structure
Allbridge acknowledged that Core and Allbridge Basic will stop working of their present type inside three months, whereas the brand new model of Core will fully take away liquidity swimming pools and swap to routing through CCTP and LayerZero to cut back pool imbalance dangers. It is a step in the precise path for Allbridge Subsequent, the place the mission goals to prioritize appropriate routing as an alternative of concentrating all transaction flows into the identical mechanism.
With the present utilization scale of Allbridge Core, this modification exhibits that the exploit goes past a mere technical incident. It’s driving the mission towards a special structure whereas demonstrating that the pool-based bridge mannequin has develop into some extent that wants alternative fairly than simply restore.

