A Flash Loan, a Skewed Pool, and $1.65 Million Gone

It took one flash loan and a few clever transactions for an attacker to walk away with $1.65 million from Allbridge, one of DeFi's cross-chain bridging protocols. The exploit, confirmed by multiple blockchain security firms, forced the team to halt its Core Bridge entirely while investigators pieced together what went wrong.

The mechanics were surgical. The attacker borrowed $1.12 million through Kamino, a Solana-based lending protocol, and used those funds to artificially skew the price ratios inside Allbridge's Solana stablecoin liquidity pools. By manipulating the pool balances, the hacker was able to extract far more value than they deposited, a classic flash loan arbitrage attack taken to its logical extreme.

Once the damage was done on Solana, the attacker bridged the stolen proceeds over to Ethereum, putting distance between the funds and the scene of the exploit. Security firms tracking the transaction trail flagged the movement quickly, but by then the funds had already crossed chains.

### Why Cross-Chain Bridges Keep Getting Hit

This is not a story the DeFi space hasn't heard before. Bridges remain one of the most structurally vulnerable pieces of crypto infrastructure, sitting at the intersection of multiple blockchains, liquidity pools, and smart contract logic. Each of those layers is a potential attack surface.

Flash loan exploits, in particular, have become a signature move for sophisticated on-chain attackers. Because flash loans require no collateral and must be repaid within a single transaction block, they give bad actors enormous temporary leverage to manipulate prices, drain pools, or trigger edge cases in protocol logic, all without putting their own capital at meaningful risk.

Allbridge's case follows a familiar pattern: a protocol operating across chains, a pool with insufficient price manipulation protections, and an attacker who understood the math better than the safeguards did.

### What Happens Next

Allbridge has not yet released a full post-mortem, but the Core Bridge remains paused as the team works to identify the exact vulnerability and determine whether user funds beyond the initial $1.65 million are at risk. The team has reportedly reached out to the attacker, a move some protocols have used successfully in the past to negotiate the return of stolen funds in exchange for a bug bounty.

For the broader market, the exploit is another reminder that DeFi's cross-chain ambitions are still running ahead of its security foundations. As total value locked across bridges remains in the billions, every successful attack raises fresh questions about whether current auditing standards and pool designs are equipped to handle well-funded, technically precise adversaries.

Solana's DeFi ecosystem, which has been gaining momentum through 2025, may face short-term confidence headwinds as users reassess bridge exposure. Ethereum-side liquidity, meanwhile, absorbs yet another wave of suspiciously sourced funds moving on-chain.