news

Allbridge Core suspends cross-chain bridge after $1.65M exploit

Allbridge, the company behind the Allbridge Core cross-chain stablecoin bridge, said it suspended the protocol as a precaution following a “security incident” that reportedly cost $1.65 million on Sunday.

The incident affected the Allbridge Core Solana deployment, and the attacker had already done so switches the stolen funds from Solana to Ethereum before transferring them to privacy pools.

“There has been a security incident at Allbridge Core,” said a post at X on Sunday. “We have suspended the protocol as a precaution while we investigate. If you have liquidity in the affected pools, please withdraw it now.”

The Allbridge Core exploit is at least the sixth cross-bridge attack since May. Bridges are attractive targets for attackers because they often hold large pools of funds that support the bridge’s assets on the destination blockchain.

Source: Lookonchain

Onchain lens informed the attacker received a flash loan of $1.12 million USDC (USDC) from Kamino to flash USDC/USDT swaps that distorted the exchange rate of the Allbridge Core stablecoin pool.

On the topic: Taiko reopens bridge after $1.7 million exploit, says users have recovered

The attacker then withdrew liquidity at the manipulated rates by paying off the USDC loan of $1.12 million and keeping the difference.

“The resulting pool imbalance created a temporary positive arbitrage window. If you took advantage of this, please consider a refund… this will go directly to compensating the affected LPs,” it added.

This was not the first time Allbridge Core was hit by a flash loan attack.

In April 2023, Albridge was is exploited for $573,000 via a flash loan attack on the Allbridge pool on the BNB chain. The attacker acted as both a liquidity provider and a swapper, and exploited a flaw in the smart contract that allowed them to manipulate swap prices, leading to a merger of $289,900 in Binance USD (BUSD) and $290,900 in USDt (USDT).

The warning is posted on the Allbridge Core website. Source: Allbridge Core

Crossed chain bridges have been targeted since May

In June, Taiko, Ethereum’s Layer 2 blockchain, urged its users to withdraw assets from the network’s bridges after attackers exploited one of the bridge’s protocols and stole $1.7 million.

Taiko reopened its bridge 11 days after completing a four-phase recovery plan.

A few weeks before the Taiko incident, A secret network has been used via an “infinite mint” bug on a vulnerable smart contract that created unsecured versions of assets wrapped in Axelar, resulting in a $4.67 million exploit.

Among other recent exploits of the bridge Gravity bridge, Verovsky bridge and Oil network.

Magazine: The British Virgin Islands Is The Major Crypto Hub No One Ever Talks About: Here’s Why

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button