Allbridge Halts Protocol After $1.65 Million Flash-Loan Exploit
Allbridge Core is a cross-chain bridge designed to move stablecoins between blockchains including Solana and Ethereum. Such protocols pool liquidity and coordinate transfers across otherwise separate networks, making them important infrastructure for decentralized finance. Their concentration of assets and reliance on smart-contract pricing also make them frequent targets, with any failure potentially exposing liquidity providers and disrupting users’ ability to move funds between chains.
On July 19, an attacker borrowed $1.12 million through a flash loan from Solana-based lending protocol Kamino and rapidly swapped USDC for USDT to distort Allbridge Core’s pool ratios, according to Onchain Lens. The maneuver enabled withdrawals at favorable rates and drained about $1.65 million. Allbridge paused the protocol and urged users to remove liquidity from affected pools. PeckShield and CertiK said the stolen assets were later bridged from Solana to Ethereum and deposited into privacy pools.
All Coverage
4 original reportsThe Backstory
The history behind this eventXRP Bridge Loses $200,000 After Fake Deposits Bypass Checks
Cross-chain bridges allow users to move assets between otherwise separate blockchains, typically by locking tokens on one network and releasing corresponding assets on another. The bridge connecting XRP Ledger and Coreum, now known as tx, relied on software to verify incoming deposits before permitting withdrawals. A failure in that verification process exposed its reserves, underscoring the persistent security risks surrounding infrastructure that links blockchain networks.
An attacker exploited the flaw by submitting fake deposits that the software accepted as genuine, then withdrew about 200,000 XRP from the bridge’s reserves, causing losses of roughly $200,000. As of Aug. 14, 2026, the operator had suspended the bridge and patched the vulnerability. It also hired blockchain forensics specialists to trace the funds and investigate the breach, and formally reported the incident to the U.S. Federal Bureau of Investigation.
Hackers Drain Over $35 Million From Bitcoin- and Ethereum-Linked Protocols
Cross-chain bridges lock assets on one blockchain and issue claims on another, allowing capital to move between otherwise incompatible networks such as Bitcoin and Ethereum. Their security depends not only on smart-contract code but also on validation logic, private keys and administrative upgrade controls. The cluster of breaches matters because none required attackers to break underlying cryptography; instead, recurring governance and permission failures allowed trusted components to release or redirect funds.
During a six-hour span ending July 23, 2026, at least three systems lost more than $35 million. AFX Trade’s Arbitrum bridge was drained of about $24.15 million, the Verus-Ethereum Bridge lost $7.54 million, and B² Network lost $3.86 million after an attacker seized the upgrade authority for its staking contract. Blockaid said the Verus incident reused the contract path and vulnerability class exploited on May 18; Verus had redeposited recovered funds into the bridge on July 8. B² suspended staking and said affected users would be fully compensated.
Axelar Cross-Chain Bridge Exploit Drains $4.67 Million
Cross-chain bridges lock assets on one blockchain and mint corresponding tokens on another. If their validation systems fail, unbacked tokens can be redeemed for real assets. The IBC bridge between Axelar Network and Secret Network had operated since early 2023. The incident underscores how bridge contracts and monitoring systems remain critical risks in the cross-chain ecosystem.
On June 10, 2026, an attacker exploited an “infinite mint” vulnerability in the Secret-side ics20-for-axelar contract, which failed to verify the source channel. The attacker minted seven types of unbacked tokens and redeemed them for about $4.67 million in assets. The incident did not come to light until June 17. Axelar subsequently disconnected Secret Network and notified law enforcement, while some of the funds flowed to Ethereum, BNB Chain and exchanges.
Gravity Bridge Suffers Key-Exposure Exploit, Losing About $5.4 Million
Gravity Bridge is a cross-chain protocol connecting the Ethereum and Cosmos ecosystems, with validators jointly authorizing asset transfers. Cross-chain bridges hold large concentrations of tokens, and stolen keys can allow attackers to bypass security controls. The incident again highlights key-management risks in DeFi infrastructure.
On-chain analyst Specter raised the alarm on May 30, 2026, saying an apparent contract-key exposure had allowed about $5.4 million to be removed from Gravity Bridge. The assets included 4.3 million USDC, 274 WETH, 434,000 USDT and 14.164 PAXG, leaving only about $85,000 in the contract. The team confirmed the following day that the bridge had been paused.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →