CYNTRI AIAutonomous DeFi
🔍SEARCH
THE BODY COUNT
HACK DATABASE·🔓

They Got Robbed the Exact Same Way in 2023, Fixed It, Then Got Robbed Again

In 2023 an attacker used a flash loan to manipulate Allbridge's pools and drained $570K. The team recovered most of it, rewrote the code, promised it could never happen again, and named the exact fix. On July 19, 2026, someone did it again for $1.65 million.

S
SYNTH·Hack Database
They Got Robbed the Exact Same Way in 2023, Fixed It, Then Got Robbed Again - CMZ investigation
Allbridge lost $1.65M to the same flash-loan pool attack it claimed to have fixed in 2023.

There is getting hacked, and then there is getting hacked the exact same way you were hacked three years ago, after telling everyone you fixed it. Allbridge managed the second one.

On July 19, 2026, Allbridge Core, the stablecoin-routing arm of the Allbridge cross-chain bridge, paused its entire protocol after an attacker drained roughly $1.65 million from its Solana liquidity pools. Security firms PeckShield and CertiK confirmed the loss. The team posted the crypto equivalent of a fire alarm on X: the protocol is paused, and if you have liquidity in the affected pools, withdraw now.

The mechanics are almost elegant in how ordinary they are. Allbridge Core does not issue wrapped tokens. It moves native stablecoins like USDC and USDT between chains using liquidity pools, and the exchange rate between the two stablecoins in a pool is calculated from their ratio. Distort the ratio, and you distort the price. The attacker took out a $1.12 million USDC flash loan from Kamino, a Solana lending protocol, and used that borrowed pile to shove the USDC/USDT pool badly out of balance. With the pool ratio warped, they withdrew assets at an artificially favorable rate, pocketed the difference, and bridged the proceeds from Solana to Ethereum, where the funds were converted to ETH and scattered across multiple addresses, per on-chain data flagged by Arkham Intelligence. The whole thing happens inside a single transaction, which is the entire point of a flash loan: the money is borrowed and repaid in the same block, so the attacker never needs capital of their own, only a crack in the pricing logic to pry open.

CyntriAI
PREDICTIVE DEFI
Stop chasing yields across five chains.
Cyntri AI agents predict, execute, and rebalance your DeFi positions using advanced predictive models.
ETHSOLARBBASEOP
Read the Whitepaper
cyntriai.org
A Cyntri AI Project

Here is where it stops being a routine DeFi exploit and becomes a CMZ story.

In April 2023, Allbridge was hit by a flash-loan attack on its BNB Chain pools. Same category. Same idea: manipulate the pool ratio, extract value at the distorted rate. That one drained about $570,000. Allbridge did what a responsible team is supposed to do. It negotiated with the attacker, recovered roughly $465,000 through a white-hat arrangement, paused, and rewrote parts of its design. And it published a postmortem that said, in plain language, exactly how it would make sure this never happened again. The quote is the whole story: "To prevent the possibility of flash loan attacks, we will deploy a single liquidity pool per blockchain. Therefore, it will not be possible to execute an exploit in a single transaction."

The logic was sound. A single-token pool has no second stablecoin to swap against, so there is no ratio to manipulate. If you only have one asset in the pool, the flash-loan trick has nothing to grab. The fix, as described, would have worked.

The 2026 attack happened on a USDC/USDT pool on Solana. Two stablecoins. A ratio to distort. Exactly the configuration the 2023 fix was supposed to eliminate. Whatever "single liquidity pool per blockchain" meant in the postmortem, it was not in force on the Solana deployment three years later. The defense they announced to the world was either never fully implemented, was rolled back, or never reached the chain where it mattered most. The attacker did not need to find a new vulnerability. They just needed to check whether the old one had actually been closed. It had not.

To be fair to Allbridge, the 2023 episode does offer one reason for cautious optimism: this is a team that has talked a hacker into giving money back before. They have a template for recovery, and they moved fast, pausing the protocol and publicly asking the arbitrage traders who profited from the temporary pricing distortion to return funds for LP compensation. Whether that works this time is harder. The 2026 theft is nearly three times larger, and the funds have already been bridged off Solana and fragmented across Ethereum addresses, which is a far messier trace than assets that stayed on one chain.

The bigger picture is unforgiving. Bridges are the honeypots of crypto: they concentrate large pools of assets in one place to back transfers, across chains with wildly different security assumptions, using pricing logic complex enough to hide inconsistencies. More than $840 million was lost to DeFi hacks in the first five months of 2026 alone, with cross-chain systems repeatedly producing the biggest single losses. By one industry count, Allbridge was at least the sixth attack on a cross-chain bridge since May. Flash loans do not create these holes. As one write-up put it, they compress time: if a pool's accounting can be pushed off balance inside a single block, the loan turns that crack into a door.

The lesson Allbridge illustrates is narrower and sharper than "bridges are risky." It is that a postmortem is a promise, and a promise is not a patch. Announcing the fix is not the same as shipping the fix on every chain, forever, including the new ones you deploy later. Allbridge told everyone precisely how it had sealed the door. Three years on, someone tried the same handle, and it opened.

The Aftermath

Allbridge kept the protocol paused while investigating and pursued recovery through the same playbook that partly worked in 2023, publicly appealing to arbitrage traders to return profits and preparing to trace the bridged funds. Recovery prospects were considered weaker than in 2023 because the loss was larger and the funds had already been moved off Solana and fragmented across Ethereum addresses. The incident became a case study in the gap between a published security postmortem and its real-world implementation, since the 2026 attack exploited exactly the two-stablecoin pool configuration the 2023 fix had promised to eliminate. It also added to a punishing 2026 for cross-chain infrastructure, which had absorbed repeated large exploits including Kelp DAO's $292M loss.

LESSONS LEARNED

!A postmortem is a promise, not a patch. Allbridge named the exact fix in 2023 - single pool per chain - then got drained in 2026 through a two-stablecoin pool that fix was supposed to eliminate. Announcing a defense is not the same as shipping it on every chain, including ones you deploy later.
!Attackers do not always need a new vulnerability. Sometimes they just check whether the old one was actually closed. The cheapest exploit is the one a team told the world it had already fixed.
!Flash loans do not create the hole; they remove the need for capital. If a pool's pricing can be pushed off balance inside one block, borrowed money turns that crack into a door - which is why single-transaction accounting integrity is the whole game for a pool-based bridge.

COMMENTS

CMZ
END OF FILE
Filed under Hack Database