Allbridge Halts After $1.65M Flash Loan Exploit
Cross-chain protocol Allbridge halted operations after a flash loan exploit resulted in a $1.65 million loss. The attacker leveraged a $1.12 million flash loan from Kamino to manipulate pool ratios and withdraw assets at favorable rates before bridging funds.
Quick Take
Attacker used a $1.12 million flash loan from Kamino to manipulate pools.
Allbridge suffered a $1.65 million loss before halting operations.
The exploit enabled withdrawal at favorable rates by distorting pool ratios.
Market Impact Analysis
BearishA significant exploit on a cross-chain protocol typically triggers immediate negative sentiment and potential sell pressure on associated assets.
Speculation Analysis
Key Takeaways
- Allbridge halted operations after a flash loan exploit drained $1.65 million from its liquidity pools.
- The attacker borrowed $1.12 million from Kamino via flash loan to distort pool ratios and withdraw assets at favorable rates.
- This is the latest DeFi exploit targeting cross-chain protocols, highlighting persistent bridge vulnerabilities.
What Happened
Cross-chain protocol Allbridge halted operations after an attacker exploited a flash loan to drain $1.65 million from its liquidity pools. The exploit used a $1.12 million flash loan from Solana-based lender Kamino to manipulate pool ratios. By distorting the balance of assets, the attacker could withdraw tokens at artificially favorable rates before bridging the funds out. The protocol acted swiftly, pausing all activities to prevent further losses. No user funds beyond the affected pools were compromised, but the incident underscores the fragility of cross-chain mechanisms that rely on price oracles and pool state.
The Numbers
The total loss settled at $1.65 million, entirely from manipulated liquidity pools. The attacker needed only a $1.12 million flash loan—a fraction of the stolen amount—to execute the scheme. Allbridge’s total value locked (TVL) dropped sharply as liquidity providers pulled funds in the aftermath. While the absolute dollar figure is modest compared to past bridge hacks, the relative efficiency of the exploit raises concerns about similar attack vectors across other protocols.
Why It Happened
The root cause was an insecure pool design that allowed flash loan-funded manipulation. The attacker borrowed heavily, skewed the asset ratios in a liquidity pool, and then withdrew at a price that did not reflect true market value. This type of exploit, often called a price manipulation attack, succeeds when protocols fail to implement robust time-weighted average pricing or oracle mechanisms that resist short-term distortions. The cross-chain nature added complexity, enabling the attacker to bridge assets immediately and obscure the trail.
What to Watch Next
- Allbridge’s post-incident audit and remediation plan—users await details on potential recovery or compensation.
- Regulatory and industry scrutiny of bridge security may intensify, especially given cross-chain exploits’ growing frequency.
- Kamino’s response and whether flash loan protocols implement stricter safeguards against malicious usage.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.