$1.65M Security Breach Forces Allbridge Core to Halt Cross-Chain Operations

$1.65M Security Breach Forces Allbridge Core to Halt Cross-Chain Operations

Following a security breach that resulted in approximately $1.65 million in losses, Allbridge Core has suspended its protocol operations. The attack reportedly involved flash loan exploitation to manipulate exchange rates within a stablecoin liquidity pool.

A cross-chain stablecoin bridge platform known as Allbridge Core announced it has temporarily suspended protocol operations following what it described as a "security incident" that allegedly resulted in the drainage of $1.65 million worth of assets on Sunday.

The security breach impacted the Solana-based deployment of Allbridge Core's infrastructure. Following the attack, the perpetrator successfully transferred the stolen cryptocurrency from Solana to the Ethereum network before subsequently routing the assets through privacy-focused pools.

Allbridge Core is experiencing a security incident. We have paused the protocol as a precaution while we investigate. If you have liquidity in affected pools, please withdraw now.

This security incident involving Allbridge Core represents no less than the sixth documented attack on cross-chain bridge infrastructure since the beginning of May. Cross-chain bridges have become increasingly popular targets among malicious actors due to the substantial pools of cryptocurrency they maintain to support bridged assets on receiving blockchains.

Transaction data
Source: Lookonchain

According to a report from Onchain Lens, the perpetrator initially secured a flash loan worth $1.12 million in USDC (USDC) from the Kamino platform, subsequently executing rapid-fire swap transactions between USDC and USDT that artificially manipulated the exchange rate within Allbridge Core's stablecoin pool.

Following the exchange rate manipulation, the attacker proceeded to extract liquidity based on the artificially distorted rates, subsequently repaying the original $1.12 million USDC flash loan while retaining the profits generated from the price differential.

The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage of it, please consider returning funds… this will go directly toward compensating affected LPs.

Cross-chain bridges targeted since May

During June, Taiko, which operates as an Ethereum layer-2 blockchain platform, issued urgent warnings to its user base recommending the immediate withdrawal of digital assets from the network's bridge infrastructure following an attack on one of its bridge protocols that culminated in losses totaling $1.7 million.

The Taiko platform resumed bridge operations approximately 11 days following the incident after successfully implementing and completing a comprehensive four-step recovery and security enhancement plan.

Just weeks prior to the security incident affecting Taiko's infrastructure, Secret Network suffered an exploitation through what was identified as an "infinite mint" vulnerability present within a compromised smart contract, which enabled the creation of unbacked versions of Axelar-wrapped digital assets, ultimately leading to a $4.67 million exploitation.

Additional bridge exploits that have occurred in recent months include security breaches affecting the Gravity Bridge platform, the Verus Bridge infrastructure, and the Butter Network protocol.