Wire
05:43ZTASNIMNEWSMourners gather at Vahdat Hall in Tehran to pay respects to Akbar Abdi05:43ZRNINTELEvacuated count reaches 220,000 in Gironde, traffic cut on highways west and south of Bordeaux05:43ZTASNIMNEWSIsraeli military attacks Nablus05:43ZSBSNEWSAUSIndian minister Dharmendra Pradhan resigns, opposition claims victory05:39ZMEHRNEWSIran Minister: Over 100 Billion Tomans Monthly Go to Art Community via Fund05:38ZABUALIEXPRIranian sailor killed in Ukrainian attack on ship in Caspian Sea05:37ZOSINTLIVEAndy Burnham says he would call out Trump to defend Britain's national interest05:37ZOSINTLIVEBerlin police release photo of 21-year-old suspect Abdul B. wanted in connection with investigation
  • S&P 500 ETF 0.10%
  • Nasdaq 0.64%
  • Nasdaq 100 1.15%
  • Dow ETF 0.48%
Terminal ↗
← The MonexusCrypto

Allbridge Core pauses cross-chain bridge after $1.65M exploit

The cross-chain bridge operator halted swaps on 20 July 2026 after an attacker used a flash loan to manipulate its stablecoin exchange rate and walk away with roughly $1.65 million.

Cross-chain bridges have been a recurring target for DeFi exploits, with cumulative losses running into the billions.
Cross-chain bridges have been a recurring target for DeFi exploits, with cumulative losses running into the billions. CoinTelegraph · illustration

Allbridge Core, a cross-chain bridge that lets users move assets between networks, halted operations on 20 July 2026 after an attacker drained roughly $1.65 million from its stablecoin pool through a flash-loan-assisted manipulation of the bridge's exchange rate.

The incident is the latest in a string of bridge-targeted attacks that have shaped how the decentralised-finance sector thinks about wrapped assets, pooled liquidity and the limits of on-chain price oracles. It also lands at a moment when regulators in the United States and Europe are sharpening rules specifically aimed at the infrastructure that lets tokens move between chains.

According to a 20 July report from CoinTelegraph, the exploit combined a flash loan with rapid swaps to distort the rate at which Allbridge Core priced one stablecoin against another. The attacker appears to have bought the cheaper side of the mispriced pair, sold it on an external venue where the rate still held, and repeated the cycle until the pool was emptied. The pause was put in place to stop further withdrawals while the team assesses the damage.

What the attacker actually did

Flash loans are a DeFi primitive that lets a borrower pull uncollateralised capital from a lending pool, execute a series of trades in a single transaction, and return the borrowed funds before the block closes. They are useful for arbitrage and refinancing; in the wrong hands, they are also a convenient amplifier for any logic that depends on a momentarily wrong price.

CoinTelegraph's account describes a sequence in which the attacker took a flash loan, used the proceeds to skew Allbridge Core's stable-to-stable rate, and then routed the cheaper stablecoin out of the bridge to capture the spread before repaying the loan. The mechanics are familiar to anyone who has watched previous bridge exploits: a rate that is correct on paper becomes briefly incorrect in practice, and the protocol pays the difference.

The size of the loss, at around $1.65 million, is small relative to the largest bridge hacks on record. The 2022 Ronin compromise took roughly $625 million; the Wormhole exploit removed about $320 million; Harmony's Horizon bridge lost close to $100 million. Allbridge itself was hit in 2023 for a sum in the low single millions. The pattern matters more than the headline number: bridges hold large pools of liquidity that are governed by code, and code has bugs.

Why bridges keep getting hit

Cross-chain bridges exist because the blockchains they connect do not, by default, know what is happening on each other. A bridge accepts a deposit on one chain, locks it, and issues a representative token on the destination chain that can later be redeemed. The locked pool is, in effect, a giant vault with an open API.

That architecture creates three recurring failure modes. The first is the smart-contract bug, where a flaw in the lock-or-mint logic lets an attacker mint unbacked tokens. The second is the validator compromise, where the off-chain signers who attest to cross-chain events are suborned and used to approve a fraudulent withdrawal. The third, the one Allbridge Core appears to be dealing with now, is the pricing assumption: the bridge treats two dollar-denominated assets as worth a dollar, but a sufficiently large or fast trader can move that rate, and the protocol has no way to notice in time.

Stable-to-stable pools are particularly exposed because their expected return is near zero, which means the liquidity buffer designed to absorb small mispricings is thin. A flash loan does not need to borrow much to push the rate.

The regulatory backdrop

Bridge operators sit awkwardly between the categories that current crypto rules were written for. They are not exchanges in the conventional sense, because they do not match buyers and sellers. They are not custodians in the plain-vanilla sense either, though they hold the underlying assets that back the wrapped tokens they issue.

The United States Securities and Exchange Commission has signalled, in a series of enforcement actions and staff statements over the past two years, that it views the issuance and redemption of bridge-wrapped tokens as a securities-relevant activity when the wrapper is sold to retail users. The European Union's Markets in Crypto-Assets regime, which came into full effect in late 2024, treats asset-referenced and e-money tokens with reserve and disclosure requirements that some bridge designs do not comfortably satisfy. The Financial Action Task Force has, separately, pressed national regulators to apply anti-money-laundering controls to cross-chain transfers.

None of those frameworks directly addresses an exploit carried out through rate manipulation in a single transaction. But each of them pushes bridge operators towards more conservative designs: smaller pools, longer confirmation windows, third-party attestations, and clearer disclosure of how a token's peg is actually maintained. Allbridge Core's pause, in that light, is not only a defensive move; it is also a window during which a regulator could reasonably ask what the protocol's risk disclosures actually said.

What we do and do not know

The CoinTelegraph report gives the size of the loss and a sketch of the attacker's path, but several details remain unsettled. The address of the exploit contract, the precise token pair involved, and the destination chain to which the proceeds were bridged have not been published in the report Monexus reviewed. The team behind Allbridge Core had not, at the time of the CoinTelegraph dispatch, issued an on-chain post-mortem, so the exact oracle or pricing module that failed is still to be confirmed.

There is also no public attribution. Bridge exploits are sometimes traced within hours through wallet clustering and exchange deposit monitoring, and sometimes drift for weeks. Whether the same actor is responsible for the 2023 Allbridge incident, or for any of the smaller bridge probes that have shown up on-chain in recent months, is an open question. CoinTelegraph does not name a suspect, and Monexus does not have independent evidence to add.

The bridge's own statement, referenced in the CoinTelegraph report, says swaps have been paused while the team investigates. Whether the pause becomes a permanent wind-down, a partial restart, or a relaunch under tightened parameters will determine whether $1.65 million ends up being the full cost of the incident or just the visible portion.

Stakes for the sector

Every bridge exploit tightens the conditions under which the surviving operators raise money and onboard users. Investors who lost money in earlier incidents are slower to provide liquidity to new pools. Institutional desks that once routed flows through bridges now demand attestations, insurance wrappers and named custodians before they touch a wrapped asset. The cumulative effect is that bridges, which started the decade as one of the more lightly regulated corners of crypto, are converging towards the compliance posture of the exchanges they were originally meant to bypass.

Allbridge Core's pause is a small event in dollar terms. It is a useful reminder that the architecture which lets a stablecoin move from one chain to another is, for the moment it moves, the most valuable piece of code in the transaction.

Monexus frames cross-chain exploits as infrastructure failures first, market-moving events second; the wire tends to lead with the dollar figure and leave the architecture for later paragraphs.

© 2026 Monexus Media · AI-native reporting from public-source material