Allbridge Core Exploit on Solana after an attacker walked away with somewhere between $1.1 million and $1.65 million in a single, tightly engineered transaction. For liquidity providers still sitting in the affected pools, every hour of delay could mean a bigger hit to their deposits.
Here's what actually happened inside that transaction — and why the exploiter's next move on Ethereum matters just as much as the attack itself.
Protocol Paused as Investigation Begins
Allbridge Core Exploit confirmed a security incident affecting its protocol and paused operations as a precaution while its team investigates. The project has not yet published a full post-mortem, but it moved quickly to limit further damage once the exploit was detected.
Liquidity providers with funds in the affected pools have been urged to withdraw immediately. Allbridge Core has not given a timeline for when — or whether — it will resume normal operations.
Allbridge Requests Arbitrage Traders to Return Funds
The pool imbalance created by the attack briefly opened a profitable arbitrage window for unrelated traders. It has publicly asked anyone who captured that profit to voluntarily send it back, sharing a dedicated wallet address for the purpose.
The team says any returned funds will go directly toward compensating liquidity providers who lost money in the exploit. It's a goodwill appeal rather than a guaranteed recovery mechanism — whether traders comply remains to be seen.

Source: Official AllBridgeCore X
Flash Loan Attack Explained
On-chain investigators at Onchain Lens traced the crypto hack news today to a classic flash loan playbook, executed entirely within one transaction:
The attacker borrowed $1.12 million in USDC through a Kamino Finance flash loan.
Rapid USDC-to-USDT swaps distorted the ratio inside Allbridge's stablecoin pool.
Liquidity was withdrawn at the now-skewed, favorable exchange rate.
The flash loan was repaid in full within the same transaction.
Roughly $1.1 million was extracted as profit.
Largest Transaction During the Attack
The single largest withdrawal tied to the hack reportedly reached $2.24 million in USDC. Onchain Lens identified the attacker's Solana wallet and is continuing to track its activity as the investigation develops.
Proprietary Angle: Attack Timeline Reconstruction
The attack was not a direct bridge drain but a liquidity manipulation exploit. The attacker first targeted the pricing mechanism inside Allbridge’s stablecoin pool, using temporary capital from a flash loan to create an artificial imbalance before withdrawing funds at distorted rates. This shows that DeFi protocols can face risks not only from smart contract bugs but also from pool pricing weaknesses.

Source: PeckshieldAlert X
Onchain Lens Assessment
Onchain Lens puts direct losses from the Solana-based exploit at more than $1.1 million, with the stolen assets later routed through privacy protocols to obscure their trail.
PeckShield Findings
PeckShield's monitoring puts the total exploit impact closer to $1.65 million and confirms the attacker bridged the stolen funds from Solana over to Ethereum shortly after the attack. Security researchers from both firms are continuing to track the funds.

Source: Onchain Lens X
Assets Bridged to Ethereum
PeckShield's on-chain data shows the exploiter moved the stolen assets across chains, converting the Solana-based Defi haul into funds now sitting on Ethereum.
Funds Mixed Through Privacy Protocols
Onchain Lens reports the stolen funds were also passed through privacy protocols. That step makes the money considerably harder to trace and significantly lowers the odds of a clean recovery.
Emergency Measures Taken: Allbridge paused Core, opened an internal investigation, and is actively monitoring the affected pools for further irregular activity.
Guidance for Liquidity Providers: Affected LPs are being told to withdraw their liquidity now and hold off on redepositing until Allbridge issues further official updates.
Compensation Efforts: The team's public appeal for arbitrage profits to be returned is aimed squarely at making affected LPs whole, though there's no formal compensation plan confirmed yet.

Source; CoinMarketCap Data
LPs Face More Than Just Smart Contract Risks
The incident highlights several risks for liquidity providers beyond traditional bridge security concerns:
Pool pricing risk: Even if a bridge contract remains active, manipulated asset ratios can create losses for LPs.
Temporary imbalance risk: Large traders or attackers can exploit sudden price differences before protocols react.
Withdrawal timing risk: LPs who remain in affected pools during an incident may face increased exposure.
Recovery uncertainty: Compensation depends on recovered funds, returned arbitrage profits, or protocol treasury support.
Why LP Monitoring Is Becoming More Important?
The Allbridge core exploit incident shows that liquidity providers need to monitor:
Emergency announcements from protocols.
Sudden pool ratio changes.
Large flash loan activity.
Unusual liquidity withdrawals.
Allbridge exploit investigation is ongoing, and a formal post-mortem report is likely once the team has a complete picture. Traders and LPs should watch for potential smart contract fixes, protocol upgrades, updates on fund recovery, and any concrete compensation plan for affected liquidity providers.
Allbridge Core exploit by a flash loan exploit on Solana, with losses estimated between $1.1 million and $1.65 million, depending on the security firm. The attacker manipulated the platform's stablecoin pool ratio using a Kamino flash loan, withdrew liquidity at distorted rates, and has since bridged the funds to Ethereum before mixing them through privacy protocols.
Allbridge has paused Core, urged LPs to withdraw, and appealed for arbitrage profits to be returned as its investigation continues. For now, affected users should follow Allbridge's official channels closely while the team works toward mitigation and possible recovery.
Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency investments carry significant risk, including exploits, hacks, and total loss of funds. Readers should conduct their own research and consult a qualified financial advisor before making any investment decisions. CoinGabbar is not responsible for any losses incurred from acting on information in this article.