The cross-chain bridge protocol Allbridge Core suffered a flash-loan and stablecoin pool exchange-rate manipulation attack on July 20. Onchain Lens on-chain monitoring shows that losses have exceeded $1.1 million. Allbridge Core has officially paused the protocol as a precaution and advised users who hold funds in the affected liquidity pools (LPs) to withdraw immediately.
Allbridge Core’s official statement was posted on X on July 20, 2026. The original text is as follows: “Allbridge Core is currently experiencing a security incident. We have paused the protocol as a preventive measure and are investigating. If you have liquidity in the affected fund pool, please withdraw immediately. The imbalance of the fund pool created a temporary positive arbitrage opportunity. If you took advantage of this, please consider returning the funds to the address below—this will be directly used to compensate the affected LP.”
The official refund address provided is 0x01a494079DCB715f622340301463cE50cd69A4D0. As of the time of reporting, the vulnerability analysis is still underway, and Allbridge Core has not yet released the final loss figure or the complete technical details of the attack.
According to BlockBeats’ on-chain detection technical analysis, the attack execution steps were as follows:
Obtain a flash loan: The attacker obtained a flash loan from Kamino as the initial capital for the attack.
Manipulate the stablecoin pool: The attacker quickly swapped USDC and USDT to alter the liquidity balance of Allbridge’s stablecoin pool, causing the pool to become imbalanced.
Extract liquidity using the manipulated exchange rate: The attacker extracted liquidity from the pool using the abnormal exchange rate created by the manipulation.
Repay the flash loan: Within the same on-chain transaction, the attacker repaid the original flash loan, completing the entire attack flow.
Fund tracking: Subsequent records show the transfer of $1.1 million and mixing via a privacy protocol.
BlockBeats’ on-chain detection shows the attack began with losses of about $1.12 million. The attacker has already transferred about $1.1 million and used a privacy protocol to mix the funds to obscure their destination. Allbridge Core’s largest single withdrawal amount was about $2.24 million, distributed in the form of USDC.
Onchain Lens on-chain monitoring shows that, as of the time of reporting, losses have exceeded $1.1 million. The official emphasized that the vulnerability analysis is still ongoing and has not released updated loss statistics.
According to Allbridge Core’s official statement on X, users holding funds in the affected liquidity pools should withdraw their liquidity immediately. The official has paused the protocol as a precautionary measure and is conducting an investigation; the latest status should follow Allbridge Core’s official announcements.
The figure of losses exceeding $1.1 million comes from Onchain Lens’ on-chain monitoring. BlockBeats’ on-chain detection records also show that the attack began with losses of about $1.12 million. As of the time of reporting, Allbridge Core has not yet published a verified final loss figure, and the vulnerability analysis is still ongoing.
As of the report on July 20, 2026, the attacker has mixed about $1.1 million via a privacy protocol, with no refund record yet. Allbridge Core’s official statement on X called on users who took advantage of the arbitrage opportunity to return the funds to the specified address for compensating affected liquidity providers.
Related News
Dutch Court Declares Knaken Crypto Platform Bankrupt Over $8M Missing Funds
Knaken Declared Bankrupt by Rotterdam Court as €7M in Customer Funds Missing
Ostium suspends trading due to a suspected oracle attack; estimated losses are about $22 million