Scram News
Crypto

Allbridge Core exploit: protocol paused after $1.65M theft

Allbridge Core exploit investigators paused the protocol after security firms traced about $1.65 million in stolen funds from Solana to Ethereum.

By Caleb Mwangi4 min read
Abstract blockchain network graphic representing cross-chain bridge infrastructure

Allbridge Core paused its protocol on Monday after PeckShield put the exploit at about $1.65 million and CertiK said the stolen funds had moved from Solana to Ethereum. By the time Allbridge acknowledged the breach, investigators were already following assets across chains.

For bridge users, the incident is less a token-sentiment story than a test of operations. Cross-chain bridges sit in the crypto market’s plumbing, and a disclosed dollar loss, named security firms and a quick shutdown give users a cleaner timeline than the vague notices that often follow smaller exploits. The open questions are practical: did the pause stop any further drain, how did the attack path work, and can Allbridge map the wallets before the funds splinter across Ethereum?

Allbridge said in a statement on X that it halted the protocol as a precaution while it investigated.

“Allbridge Core is experiencing a security incident. We have paused the protocol as a precaution while we investigate.”
Allbridge, statement on X

Its wording was narrow. Bridge users tend to read such pauses as an attempt to freeze activity before a contract flaw becomes a broader liquidity problem. Allbridge did not, in the statement cited by scramnews, say how many users were affected or lay out a recovery path. The hard public numbers, for now, came from outside investigators rather than the protocol itself.

PeckShieldAlert said on X that “Core was exploited for ~$1.65M,” while CertiK Alert said the attacker had bridged the stolen assets from Solana to Ethereum. That cross-chain detail matters. Once funds leave the source chain, investigators are no longer looking only at the original pool or contract state; they are tracking wallets, bridges and swap routes on a second network.

“Core was exploited for ~$1.65M.”
PeckShieldAlert, post on X

Flash-loan mechanics were part of the early account in initial reporting on the incident. In practice, that usually means the attacker borrowed large amounts of liquidity inside a single transaction, used it to distort or exploit contract logic, and repaid the loan before the transaction closed. The structure does not identify the contract weakness by itself. It does explain why teams often pause first and explain later.

Onchain, the clock runs faster. The moment funds land on Ethereum, each swap or bridge hop can widen the search area for investigators and reduce the odds of a clean recovery. That makes the pause and the public timeline part of the same story: one is an operational control, the other tells users whether the team and outside monitors are watching the same wallets.

A pause, though, is only a first-response tool. It can stop fresh flows through a protocol, but it cannot reverse completed transactions or guarantee that liquidity providers are insulated from losses already crystallised onchain. Follow-up disclosure usually determines whether a bridge incident stays contained or turns into a longer confidence problem.

For Allbridge, the next step is likely to be operational detail rather than reassurance. Users will want to know which pools or routes were touched, whether the protocol’s Solana-side contracts remain isolated from the bridged funds now on Ethereum, and whether any white-hat or validator measures are possible before the assets are mixed further. Security firms have become the first public interpreters in incidents like this because they can publish wallet-level observations faster than most protocol teams can produce a full incident report.

Crypto infrastructure incidents carry more market weight than promotional token headlines when they expose the controls behind transfers between chains. This exploit is not only a loss event; it is a test of response speed and disclosure. A fast, specific account from Allbridge could help limit second-order damage to confidence. A slow one would leave users relying on outside alerts and block-by-block tracking to work out whether the pause contained the breach or merely marked the point at which the protocol acknowledged it.

Caleb Mwangi

Crypto correspondent covering bitcoin, ether, altcoins and on-chain markets. Reports from Singapore.

Related