Allbridge Core Pauses Cross-Chain Bridge After $1.65M Exploit

Allbridge Core has paused its cross-chain bridge operations following a $1.65 million exploit that leveraged a flash loan and rapid stablecoin swaps to manipulate the protocol’s exchange rate, the project team announced Monday.

The attacker exploited a vulnerability in Allbridge Core’s stablecoin exchange rate mechanism, using a flash loan to borrow a large sum of USDC, then executing a series of rapid swaps across supported chains to artificially inflate the price of one stablecoin relative to others. This allowed the attacker to withdraw more value than deposited, netting approximately $1.65 million across Ethereum, BNB Chain, and Polygon.

“We detected the exploit within minutes and immediately paused the bridge to prevent further losses,” Allbridge Core said in a statement on X. “The vulnerability was in the rate calculation logic for stablecoin pools. User funds not involved in the exploited pools remain safe.”

Blockchain analytics firm PeckShield confirmed the attack vector, tracing the flash loan to a major DeFi lending protocol on Ethereum mainnet. The attacker converted the borrowed USDC through a series of cross-chain swaps on Allbridge Core, exploiting a time-weighting flaw in the protocol’s oracle that failed to account for rapid price manipulation within a single block.

The stolen funds — approximately 1.65 million USDC equivalent — have been bridged to Ethereum and partially deposited into Tornado Cash, complicating recovery efforts. Allbridge Core said it is working with blockchain forensic firms and law enforcement to trace the funds.

“Cross-chain bridges remain one of the highest-risk primitives in DeFi,” said Igor Igamberdiev, research analyst at The Block. “This exploit highlights how oracle manipulation and flash loans can be combined across multiple chains, where monitoring and response times are inherently slower.”

Allbridge Core has not announced a timeline for resuming operations. The team said it will deploy a fix for the rate calculation logic, engage a third-party audit, and implement additional circuit breakers before reopening the bridge. The protocol had approximately $45 million in total value locked across its supported chains prior to the pause.

This marks the second significant bridge exploit in 2026, following the $3.2 million Wormhole incident in March. According to DefiLlama data, bridge exploits have accounted for over $2.8 billion in losses since 2020, making them the largest single category of DeFi hacks.

Allbridge Core advised users to avoid interacting with the protocol until further notice and to revoke any active token approvals to the bridge contracts as a precaution.

Source: Cointelegraph