Wire
03:11ZTHEJERUSALTrump concerned over Middle East interceptors, will not escalate with Iran03:05ZTASNIMNEWSAmbulance buses stationed every 10 km on Mehran and Chazaba borders03:03ZPRESSTVOver 1,000 Palestinian children displaced in West Bank this year – UNICEF02:57ZAMKMAPPINGRussian drone hits cargo ship in western Black Sea02:54ZWARMONITORDrone reported flying over Kryvyi Rih, Ukraine02:51ZBRICSNEWSUkrainian President Zelenskyy to meet President Trump at White House next week02:50ZAMKMAPPINGRussia launches 6 ballistic missiles at Kyiv's Solomianskyi district overnight02:47ZTASNIMNEWS22 trains to provide free transport for Arbaeen pilgrims to Shalamcheh border in Khuzestan
  • S&P 500 ETF 0.10%
  • Nasdaq 0.64%
  • Nasdaq 100 1.15%
  • Dow ETF 0.48%
Terminal ↗
← The MonexusCrypto

Allbridge hit for $1.65M as cross-chain bridges keep bleeding out

A weekend exploit drained roughly $1.65 million from Allbridge Core, with the attacker routing proceeds from Solana to Ethereum. The incident lands the same week Washington reopened its fight over who gets to police decentralised finance.

Orange graphic placeholder with "CRYPTO," "MONEXUS NEWS," and "— DESK —" text, noting no photograph is on file.
Orange graphic placeholder with "CRYPTO," "MONEXUS NEWS," and "— DESK —" text, noting no photograph is on file. Monexus News

Roughly $1.65 million left Allbridge Core in the early hours of 20 July 2026, with the attacker routing stolen funds from Solana to Ethereum before the protocol's team could intervene. The project said it had paused the protocol as a precaution and was urging users to stop interacting with its contracts while investigators traced the cash. The incident is the latest line item in a running ledger of cross-chain bridge exploits that has quietly become the most expensive class of failure in decentralised finance.

The mechanics are now depressingly familiar: an attacker finds an edge case in the bridge's pricing or verification logic, mints or releases assets they never deposited, then funnels the proceeds through a chain hop designed to frustrate forensic tracing. Allbridge did not, in its public statement on the day, identify the specific vulnerability. What it did confirm is the directional pattern, Solana out, Ethereum in, that has come to characterise the second half of this attack cycle.

The bridge problem the industry keeps rediscovering

Cross-chain bridges exist because the rest of decentralised finance does not. Bitcoin does not natively talk to Ethereum. Solana does not natively talk to Avalanche. Bridges are the bazaars, money changers and bonded warehouses that knit these otherwise walled gardens into a single addressable market. They also concentrate risk in a way that the underlying chains do not. A chain can be attacked at its consensus layer, which is hard, or at its application layer, where the attack surface is the size of the smart-contract surface. A bridge sits between the two and tends to combine the worst properties of each: large custodied reserves, opaque verification logic, and liveness dependencies on a small set of off-chain operators.

The history is not subtle. Ronin lost more than $600 million in March 2022. Wormhole lost around $320 million in February 2022. Harmony's Horizon bridge lost close to $100 million in June 2022. Nomad lost roughly $190 million in August 2022. Multichain, which had become the default rail for cross-chain liquidity, suffered an exit in July 2023 that emptied out close to $125 million and effectively ended the project. The Allbridge figure is small by comparison, which is itself a kind of indictment: even a relatively modest exploit, in a market that has been on notice for four years, still clears the protocol.

The defenders argue, with some justification, that each of these incidents involved a distinct technical failure mode, not a single recurring bug class. Ronin was a compromised validator set. Wormhole was a signature verification bypass. Horizon was a hot-wallet compromise. Nomad was a poorly initialised merkle root. Allbridge is being analysed now; the public post-mortem will determine which category this one belongs to. The critics counter that the point is not the specific bug. The point is the category. Bridges hold liquidity, advertise interoperability, and operate as custodians without being regulated, audited or capitalised as custodians. Until the architecture changes, the failures will keep arriving.

The Washington fight that just reopened

Two days before the Allbridge exploit, US Senator Cynthia Lummis put a marker down on the underlying policy question. "If something is genuinely decentralised, it should not be regulated like a bank," she said in remarks circulated on 19 July 2026. The line is the cleanest articulation of an argument that has been building inside the crypto-policy community for the better part of a decade: that the choice regulators face is not whether to police decentralised finance but whether to police it as banking, securities dealing, money transmission, or none of the above.

The bank framing is the one US prudential regulators have reached for most readily. Treat a stablecoin issuer as a bank, the argument goes, and you solve the deposit-insurance and reserve-quality questions at a stroke. The cost is that the resulting entity looks a lot like a custody bank, with the capital and disclosure requirements that implies. The decentralised-finance counter is that the comparison is doing more work than it can bear. A protocol that holds collateral algorithmically, has no CEO, no board, no head office, and no customer relationship does not fit cleanly into a framework built around those things. Force it in and either the protocol migrates, the banks absorb it, or the activity goes underground.

Lummis's framing matters because it is the language that has shaped the legislative drafting now working its way through the Senate. The structural question for the next eighteen months is whether US law ends up with a category that recognises genuinely decentralised infrastructure as something distinct from intermediated finance. If it does, the bridge problem becomes a regulated problem. If it does not, the bridge problem becomes a self-insurance problem, and every protocol either raises a war chest large enough to absorb a worst-case loss or quietly passes the residual risk to its users.

What the attackers actually know

The pattern of the last two years is worth naming. The big hauls, Ronin, Wormhole, Harmony, Nomad, Multichain, were not all pulled off by a single operation. What they shared was a discovery process. Once a bridge ships a non-trivial upgrade, the assumption inside the security community is that someone, somewhere, will spend the weeks afterward looking for the gap the upgrade opened. The defender's clock is the time between deployment and first adversarial probe. The attacker's clock is the time it takes to convert a probe into a profit. Bridges have lost that race repeatedly because their defenders have to win every time and the attackers have to win once.

The Allbridge incident is small in dollar terms, but it lands inside that pattern. The protocol had been operating long enough that its code base was public, its documentation was public, and its audit history was public. An attacker willing to spend a week reading the relevant contracts and a few thousand dollars on tooling could in principle identify the same gap the production team missed. That is the structural condition of open-source financial infrastructure. It is also, in most of the rest of the software industry, not treated as a regulatory problem. Banks are allowed to fail in private because deposit insurance catches the customer. DeFi protocols fail in public because there is no insurance, no backstop, and no resolution authority. The user carries the loss and learns, in some cases, not to come back.

What to watch next

Two concrete items. First, the Allbridge post-mortem. The protocol's team has indicated that an investigation is underway; the timing and the granularity of the public write-up will determine how much of the $1.65 million can be plausibly recovered, and how much of the architectural gap gets closed before the next operator copies it. Second, the legislative text. The Senate's market-structure bill has been the vehicle for the decentralised-finance carve-out conversation; the markup schedule and the version of the definition of "decentralised" that survives committee will set the terms under which the next round of bridge operators either register, restructure, or relocate.

Neither item resolves the underlying tension. Bridges exist because the rest of decentralised finance does not interoperate natively. Bridges will keep getting attacked because they concentrate custody without the safeguards custody requires. The only durable answer is one that addresses the concentration, which is an engineering question, and the regulation, which is a political question, on the same timeline. Right now those timelines are not aligned. The ledger on which that misalignment gets measured, in dollar terms, is the ledger Allbridge just added another line to.

Wire provenance

This editorial synthesis draws on the following public wire/social posts:

  • https://t.me/s/cointelegraph
  • https://t.me/s/cointelegraph
  • https://t.me/s/cointelegraph
Intelligence ThreadFollow on terminal ↗
© 2026 Monexus Media · AI-native reporting from public-source material