Allbridge Suspends Core Protocol After $1.65M Solana Flash Loan Exploit

TheNewsCryptoОпубліковано о 2026-07-20Востаннє оновлено о 2026-07-20

Анотація

Cross-chain protocol AllBridge Core suspended operations after suffering a $1.65 million flash loan exploit on its Solana deployment. The attacker manipulated a stablecoin pool's exchange rate using a $1.12 million USDC loan from Kamino, creating a price imbalance to perform a profitable arbitrage. Stolen funds were moved to Ethereum via privacy pools. This is the protocol's second such attack, following a $573,000 exploit in April 2023. The suspension causes operational delays, reduces cross-chain liquidity, and highlights persistent security vulnerabilities in bridge protocols and automated market maker systems.

Cross-chain platform AllBridge Core shut down its operations following a security issue that resulted in the loss of $1.65 million on Sunday. The hack specifically occurred within the AllBridge Core deployment on the Solana blockchain. The attacker transferred the funds stolen via the bridge from Solana to the Ethereum blockchain. The hacker swiftly transferred the stolen funds through privacy pools to cover his tracks.

The perpetrator executed a well-thought-out flash-loan strategy to influence the exchange rate in the pool for stablecoins. As per on-chain data, the hacker took out a loan of $1.12 million in USDC from the lending platform Kamino. Quick switching between USDC and USDT led to a price imbalance within the pool balance. This price imbalance created a favorable arbitrage opportunity for the perpetrator.

The exploiter then took the liquidity from the pool at exaggerated prices to gain huge profits. The profit earned after repayment of the Kamino loan was retained by the perpetrator as loot. The entire trade reveals major flaws in the mathematical equation of the automated market maker pricing system.

Recurrent Cross-Chain Bridge Attacks

This particular event marks the second instance of an attack on Allbridge Core via a flash loan hack, after a previous $573,000 heist targeting its BNB Chain pools in April 2023. In addition, pausing the bridge would mean that there are operational delays, with the process of sending funds across chains coming to a temporary halt. This would have implications not only for trading operations but would reduce the possibility of the liquidity needed by traders and institutions being moved across.

At the same time, there is a threat that long-term protocol outages will mean the loss of revenue streams due to reduced transactions, thus making users and liquidity providers consider alternative means of bridging. Finally, security pauses in cross-chain protocols act as a reminder about the security challenges associated with liquidity pools, thus requiring investors to change their risk management strategy for bridges.

Highlighted Crypto News:
FTX Bankruptcy Estate Plans $900 Million Distribution, Total Payouts Hit $10 Billion

TagsBlockchainCORECore chainCryptocurrencyETHEREUMEthereum (ETH)SolanaSolana (SOL)

Трендові криптовалюти

Пов'язані питання

QWhat was the main action taken by Allbridge Core after the security incident?

AAllbridge Core shut down its operations, suspending its core protocol following the exploit.

QWhat type of attack strategy did the hacker use in the Allbridge exploit?

AThe hacker executed a flash loan strategy, specifically taking out a large USDC loan from the Kamino lending platform on Solana.

QHow did the attacker's actions create an opportunity for profit?

ABy quickly swapping between USDC and USDT, the attacker created a price imbalance in the liquidity pool, which allowed them to withdraw liquidity at exaggerated prices for a large profit after repaying the flash loan.

QWhat does the article mention about previous similar incidents involving Allbridge?

AThe article states this is the second flash loan attack on Allbridge Core, with a previous heist of $573,000 targeting its BNB Chain pools in April 2023.

QWhat are some potential consequences of a core protocol being paused, as mentioned in the article?

AConsequences include operational delays for cross-chain transfers, reduced liquidity movement for traders and institutions, potential loss of revenue from reduced transactions, and users possibly seeking alternative bridging solutions.

Пов'язані матеріали

Amidst Capital's Encirclement, Decentralization is the Sole Defense for Public Blockchains

In a landscape dominated by power and profit motives, the author argues that decentralization is not merely one desirable feature among many in blockchain design—it is the singular, non-negotiable defense against corporate and capital capture. The article adopts a Machiavellian, realist perspective on human institutions, positing that businesses will inevitably attempt to co-opt any valuable network to protect their profits and dominance. While external attacks like 51% forks are often discussed, the greater existential risk is internal capture—the gradual erosion of a protocol’s neutrality by vested interests, as seen historically with platforms like Visa and Google. The piece critiques permissioned chains, highly centralized “permissionless” layer-1s, and layer-2s without sufficient decentralization (e.g., single sequencers) as inherently vulnerable. These compromised systems, promoted by established financial players, are framed as delaying tactics to stifle truly open networks that threaten existing high-fee, inefficient business models. Real-world examples, such as closed enterprise consortiums that exclude competitors, illustrate how such systems cement oligopolies rather than foster innovation. The author concludes that while decentralized protocols like Ethereum are imperfect and costly to operate, they represent the only viable long-term equilibrium. In a market where value naturally flows to the most secure and neutral settlement layer, only maximally decentralized public blockchains can resist being subsumed by capital and powerful incumbents.

Foresight News11 хв тому

Amidst Capital's Encirclement, Decentralization is the Sole Defense for Public Blockchains

Foresight News11 хв тому

Who Decides the Rules of Bitcoin? BIP-110 Ignites Governance Debate

Bitcoin's governance is once again at the center of a heated debate, this time ignited by BIP-110, the "Reduced Data Temporary Softfork." This proposal aims to curb non-monetary data (like inscriptions and Runes) by introducing seven new consensus-layer restrictions over a year, such as limiting new output scripts to 34 bytes and restoring the OP_RETURN cap to 83 bytes. The controversy stems from BIP-110's fundamental shift: it moves the battle against "spam" from node relay and miner policies to the consensus layer, rendering currently valid transactions invalid. Supporters, arguing that default policy governance has failed (highlighted by Bitcoin Core v30's relaxation of OP_RETURN limits), see this as necessary to protect node resources and Bitcoin's monetary focus. Opponents, led by figures like Michael Saylor and Adam Back, warn it dangerously centralizes governance. Saylor listed 110 reasons against it, criticizing its low 55% miner activation threshold and potential for chain splits. Back emphasized Bitcoin's "permissionless" ethos, arguing no single group should impose value judgments via consensus rules. Further complicating matters, technical critiques suggest BIP-110 may be technically circumventable, and a "BlockSlop" vulnerability in its upgrade path poses a consensus risk. The debate has drawn in diverse stakeholders: miners (with pools like Ocean signaling support and Foundry polling clients), node operators (like Bitcoin Knots), and new players like corporate treasury holder MicroStrategy (Saylor), whose market influence adds a novel dimension. Ultimately, BIP-110 acts as a governance stress test, exposing the unresolved question: who decides Bitcoin's rules? It pits the authority of miners, node operators, developers, and capital holders against each other, with each side claiming to defend Bitcoin's core principles of neutrality and security.

marsbit27 хв тому

Who Decides the Rules of Bitcoin? BIP-110 Ignites Governance Debate

marsbit27 хв тому

Who Decides Bitcoin's Rules? BIP-110 Ignites Governance Debate

Title: Who Decides Bitcoin's Rules? BIP-110 Ignites Governance Debate A new technical proposal, BIP-110 (Reduced Data Temporary Softfork), has sparked a fundamental governance debate within the Bitcoin community. It aims to impose new consensus rules for one year to limit non-financial data (like inscriptions and Runes) on-chain, moving beyond simple node and miner policy filters to invalidate currently valid transactions. Supporters argue that default policies have failed due to workarounds, necessitating consensus-layer changes to protect Bitcoin's core monetary function from data spam. Critics, including Michael Saylor and Adam Back, contend this dangerously centralizes judgment, undermines permissionlessness, and sets a risky governance precedent. They advocate for market-based solutions like fees or Layer 2s instead. The debate exposes deeper tensions: miners are divided on activation; node operators assert their sovereignty; Bitcoin Core developers influence defaults without direct accountability; and large corporate holders like MicroStrategy now wield narrative influence. Technically, BIP-110 may not fully block data and carries a disclosed consensus bug risk. Ultimately, BIP-110 acts as a stress test, forcing the community to confront the unresolved question: who legitimately decides what Bitcoin is and how it evolves, amidst competing claims from miners, nodes, developers, and capital holders.

链捕手39 хв тому

Who Decides Bitcoin's Rules? BIP-110 Ignites Governance Debate

链捕手39 хв тому

Zcash's New Node Zakura Goes Live: Privacy Payments Can Reach 50,000 TPS, Aiming to Rival Visa and Mastercard

Zcash, a privacy-focused cryptocurrency, has launched a new full node software called Zakura version 1.0.0. Developed by Zcash co-founder Sean Bowe and Dev Ojha, with private ZEC donations, its goal is to enable Zcash to process over 50,000 transactions per second (TPS)—matching the scale of Visa and Mastercard—while maintaining full transaction privacy and verifiability. This addresses a key bottleneck, as Zcash currently handles only about 1 private transaction per second. Zakura is a fork of the Zcash Foundation's Zebra node. It features chain pruning and snapshots, reducing disk usage and allowing new nodes to sync in under two minutes. It also offers compatibility with the legacy `zcashd` client interface. The scalability challenge stems from the large data size of privacy proofs. Bowe's Tachyon project aims to use recursive proofs to reduce consensus-layer data needs from ~500 MB/s to ~100 MB/s. For wallet scalability, Valar Group is researching Private Information Retrieval (PIR) tech to allow wallets to fetch their data privately. Zakura supports fast block propagation and the upcoming "Ironwood" network upgrade (NU6.3), scheduled for activation around July 28th. Ironwood was created to contain a critical inflation bug discovered in the Orchard shielded pool in May 2024. The fix uses "turnstiles" to trap any counterfeit ZEC created during the vulnerability period within the shielded pool, preventing it from entering circulation and restoring supply integrity.

marsbit54 хв тому

Zcash's New Node Zakura Goes Live: Privacy Payments Can Reach 50,000 TPS, Aiming to Rival Visa and Mastercard

marsbit54 хв тому

Торгівля

Спот

Популярні статті

Як купити CORE

Ласкаво просимо до HTX.com! Ми зробили покупку CORE (CORE) простою та зручною. Дотримуйтесь нашої покрокової інструкції, щоб розпочати свою криптовалютну подорож.Крок 1: Створіть обліковий запис на HTXВикористовуйте свою електронну пошту або номер телефону, щоб зареєструвати обліковий запис на HTX безплатно. Пройдіть безпроблемну реєстрацію й отримайте доступ до всіх функцій.ЗареєструватисьКрок 2: Перейдіть до розділу Купити крипту і виберіть спосіб оплатиКредитна/дебетова картка: використовуйте вашу картку Visa або Mastercard, щоб миттєво купити CORE (CORE).Баланс: використовуйте кошти з балансу вашого рахунку HTX для безперешкодної торгівлі.Треті особи: ми додали популярні способи оплати, такі як Google Pay та Apple Pay, щоб підвищити зручність.P2P: Торгуйте безпосередньо з іншими користувачами на HTX.Позабіржова торгівля (OTC): ми пропонуємо індивідуальні послуги та конкурентні обмінні курси для трейдерів.Крок 3: Зберігайте свої CORE (CORE)Після придбання CORE (CORE) збережіть його у своєму обліковому записі на HTX. Крім того, ви можете відправити його в інше місце за допомогою блокчейн-переказу або використовувати його для торгівлі іншими криптовалютами.Крок 4: Торгівля CORE (CORE)Легко торгуйте CORE (CORE) на спотовому ринку HTX. Просто увійдіть до свого облікового запису, виберіть торгову пару, укладайте угоди та спостерігайте за ними в режимі реального часу. Ми пропонуємо зручний досвід як для початківців, так і для досвідчених трейдерів.

346 переглядів усьогоОпубліковано 2024.12.13Оновлено 2026.06.02

Як купити CORE

Обговорення

Ласкаво просимо до спільноти HTX. Тут ви можете бути в курсі останніх подій розвитку платформи та отримати доступ до професійної ринкової інформації. Нижче представлені думки користувачів щодо ціни CORE (CORE).

活动图片