Allbridge Suspends Cross-Chain Bridge After $1.65M Exploit

Featured in:
abcd

Allbridge, the company behind the Allbridge Core cross-chain stablecoin bridge, said it had paused the protocol as a precaution following a “security incident” that reportedly resulted in the leak of $1.65 million on Sunday.

The incident impacted Solana’s deployment on Allbridge Core, which the attacker had already done bridged stolen funds from Solana to Ethereum before moving them to privacy pools.

sadasda

“A security incident occurred at Allbridge Core,” the statement said post on Sunday at X. “We have paused the protocol as a precautionary measure while we investigate. If you have liquidity in the affected pools, please withdraw now.”

The Allbridge Core exploit is at least the sixth cross-chain bridge attack since May. Bridges are attractive targets for attackers because they often hold vast pools of funds that support the bridged assets on the target blockchain.

Source: Lookonchain

Onchain Lens reported the attacker issued a flash loan of 1.12 million USDC (USDC) from Kamino, followed by a rapid USDC/USDT swap that distorted the exchange rate of the Allbridge Core stablecoin pool.

Related: Users say Taiko reopens bridge after $1.7 million exploit

The attacker then withdrew liquidity at manipulated interest rates, repaying the $1.12 million USDC loan and keeping the difference.

“The resulting imbalance in the pool has created a temporary positive arbitrage window. If you have benefited from this, please consider refunding the funds… they will go directly to compensating the affected LPs,” he added.

This wasn’t the first time Allbridge Core was hit by a flash loan attack.

In April 2023, Allbridge was exploited for $573,000 in a flash loan attack on the Allbridge pool on the BNB network. The attacker acted as both a liquidity provider and a swapper and exploited a vulnerability in the sharp contract that allowed him to manipulate swap prices, leading to the leak of $289,900 in Binance USD (BUSD) and $290,900 in USDt (USDT).

Warning posted on the Allbridge Core website. Source: Allbridge Core

Since May, the target has been cross-chain bridges

In June, Taiko, Ethereum’s layer 2 blockchain, insisted its users withdraw their assets from the network’s bridges after attackers exploited one of the bridge’s protocols and stole $1.7 million.

Taiko reopened its bridge 11 days later after completing a four-stage repair plan.

A few weeks before the Taiko incident A secret network was used via an “infinite mint” bug in a vulnerable sharp contract that created insecure versions of Axelar-packaged assets, leading to a $4.67 million exploit.

Other recent bridge exploits included Gravity bridge, Verus Bridge and Butter network.

Warehouse: The British Virgin Islands is the top cryptocurrency hub that no one ever talks about: here’s why

abcd
sadasda

Find us on

Latest articles

Related articles

See more articles

Tesla’s earnings put the spotlight back on the 11,509...

Reference: AND Tesla's earnings put the spotlight back on the 11,509 BTC treasure Tesla's upcoming second-quarter earnings report brings...

Aave Selects Chainlink CCIP as Default Standard for Cross-Chain...

Reference: Aave management Aave Selects Chainlink CCIP as Default Standard for Cross-Chain sGHO Aave governance has changed such that...

The President of Nigeria signs an executive order on...

Nigerian President Bola Ahmed Tinubu has addressed what his office called fragmented regulation of digital assets.Special Advisor...

The strategy raises $263.5 million through the sale of...

Strategy, the world's largest corporate holder of Bitcoin, is raising up-to-date capital by selling its Class A...

Crypto institutions move beyond audits as trust signals weaken:...

According to Hacken, institutional investors are moving beyond shrewd contract audits after conventional trust signals such as...

Will the US get CLARITY this week? Bitcoin’s fresh...

TRANSPARENCY is based on Trump's ethicsPolymarket suggests the CLARITY Act's chances of passing this year are just...