Allbridge Core Pauses After $1.66M Solana Exploit Exposes Pool-Based Bridge Vulnerability
Allbridge Core, a protocol that facilitates cross-chain transactions, has temporarily paused operations after suffering an exploit on the Solana blockchain. The incident, which occurred on July 19 at around 17:51 UTC, resulted in approximately $1.66 million being drained from the protocol's liquidity pools.
The attack took advantage of a weakness in Allbridge Core's pool-based swap design, which relies on a virtual balance to maintain internal valuation pegs. The exploit occurred when same-asset swaps were executed consecutively in the same pool, causing a deviation between actual and recorded balances that was large enough for the attacker to extract value.
Allbridge has stated that user liquidity outside of the affected pools is not directly threatened, but the project recommends that LPs withdraw their funds from the affected pools as they no longer generate yields. The incident has also prompted Allbridge to accelerate its plans to switch to a new architecture, which will completely remove liquidity pools and rely on routing via CCTP and LayerZero.




