Allbridge Core has paused operations following an exploit on Solana that drained approximately $1.66 million from the protocol’s liquidity pools in a single transaction at around 17:51 UTC on July 19, according to a new announcement from the project.
The incident is notable not only because of the size of the loss, but also because Allbridge Core handles significant usage, with over 890,000 wallets and a TVL of over $24 million according to figures on its homepage. This incident also reopens questions about the safety of liquidity pool-based bridge models.
Allbridge Core pauses after Solana exploit
Immediately upon detecting the incident, Allbridge paused Core while investigating, noting that it took the team about 25 minutes to identify and begin shutting down the affected functions. The incident occurred on Solana and was confirmed by the project in a newly released technical post-mortem.
Allbridge Core is experiencing a security incident.
We have paused the protocol as a precaution while we investigate.If you have liquidity in affected pools, please withdraw now.
The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage… pic.twitter.com/Ovg7yT35SM
— Allbridge (@Allbridge_io) July 19, 2026
Allbridge stated that the damage was contained to the two relevant pools, while private keys and user wallets were not compromised. In the initial phase of handling the issue, the project shifted its focus to limiting the spread rather than allowing the protocol to continue operating normally while the pool state was distorted.
Pool-based swap design exposed a weakness
According to Allbridge’s technical documentation, Core uses a stablecoin liquidity pool model with a virtual balance to maintain internal valuation pegs. This design allows the bridge to operate without wrapped assets, but it also leaves the system heavily dependent on how the pool handles the discrepancy between actual and recorded balances.
According to the project, the vulnerability emerged when same-asset swaps were executed consecutively in the same pool. Each subsequent swap pushed the internal state further away from the actual liquidity, and when a flash loan was used as leverage, this deviation was large enough for the attacker to extract value before the rebalancing mechanism could react.
This incident shows that the issue lies in the pool-based swap logic when exploited in a concentrated sequence of transactions, rather than in Solana as an independent infrastructure.
About $1.66 million was drained from liquidity pools
According to the post-mortem, the exploit occurred at around 17:51 UTC on July 19, and the total value drained from liquidity pools was approximately $1.66 million, including about 1,118,239 USDC and 538,692 USDT. Based on the project’s description, the attacker initiated the attack with a flash loan of around 1.12 million USDC from Kamino, then executed a series of swaps to distort the pool ratio before withdrawing liquidity at the skewed price.
Nine-step exploit flow. Source: Allbridge
The money flow did not stop on Solana after that. According to Allbridge and forensic partners, they traced approximately $1.63 million, with a portion bridged to Ethereum and then passing through channels such as Railgun, NEAR Intents, and Zcash Orchard. Dispersing through multiple layers like this makes the tracking and recovery process significantly more complex.
Allbridge moves to contain the damage
Allbridge prioritized locking the affected parts before reopening routes that do not rely on liquidity pools. According to the post-mortem, the bridge has now resumed on these routes, while pool-based swaps remain disabled as a safety measure. The project is also keeping the liquidity pool page open so LPs can withdraw their funds, while recommending they withdraw liquidity early as the pools no longer generate yields as before.
Allbridge stated that user liquidity outside the affected pools is not directly threatened. The project also subsequently called on anyone who took advantage of the temporary price discrepancy after the incident to consider returning those profits to help compensate affected LPs.
The incident speeds up a shift to a new architecture
Allbridge stated that Core and Allbridge Classic will cease operating in their current form within three months, while the new version of Core will completely remove liquidity pools and switch to routing via CCTP and LayerZero to reduce pool imbalance risks. This is a step in the right direction for Allbridge Next, where the project aims to prioritize suitable routing instead of concentrating all transaction flows into the same mechanism.
With the current usage scale of Allbridge Core, this change shows that the exploit goes beyond a mere technical incident. It is driving the project toward a different architecture while demonstrating that the pool-based bridge model has become a point that needs replacement rather than just repair.

