Allbridge's $1.65M Replay: The Collateral Damage of Unfixed Code
ChainChain
The $1.65 million exploit on Allbridge Core wasn't a sophisticated zero-day. It was a rerun of a show that premiered in 2023. Same stage. Same script. Slightly larger audience. And the industry yawned.
Allbridge Core is a cross-chain stablecoin bridge using AMM pools to facilitate swaps between Solana and EVM chains. Launched to capture the demand for asset mobility, it operates on a simple premise: pool ratios determine price. No external oracles. No slippage protection. Just trust in the arithmetic of liquidity. For a bridge that handles millions in TVL, this is like building a house on sand and calling it a fortress.
On March 2025, an attacker borrowed a flash loan from Kamino on Solana, executed a series of swaps that skewed the USDC/USDT pool ratio, then extracted $1.65M in value. The mechanics are textbook: manipulate the price oracle (the pool itself) through a large trade, then profit from the discrepancy before the pool rebalances. I've seen this pattern in multiple audits I conducted in 2020–2022. The fix is trivial: integrate a trusted price feed like Chainlink, enforce slippage limits, or use a constant product formula with invariant checks. Yet Allbridge left the same door open. Why? Because the engineering team prioritized speed over resilience. In 2023, a nearly identical attack drained a similar amount on BNB Chain. The response then? A pause, a plea, and a promise to learn. The same pattern, repeated.
Let’s dissect the mechanics. The attacker initiated a flash loan of 10 million USDC from Kamino. Using that as ammunition, they executed a series of swaps against Allbridge’s USDC/USDT liquidity pool. With each trade, the pool ratio shifted—temporarily making USDT cheaper relative to USDC. The attacker then swapped back the cheaper USDT for USDC, netting a surplus. Twelve trades later, the profit was $1.65M. No complex smart contract tricks. No reentrancy. Just a brute-force manipulation of a naive pricing model. The same attack that worked on Ellipsis Finance, on UST de-pegging, and on dozens of other pools. The signature says it all: "Arbitrage doesn't create value; it exposes inefficiency." Here, the inefficiency was the bridge itself.
Retail traders will blame the hacker. But the real culprit is a governance culture that tolerates known bugs. When a project survives its first exploit and doesn’t fundamentally change its design, it sends a signal: we value uptime over safety. In traditional finance, a brokerage that double-charges clients faces regulatory action. In crypto, we call it a 'learning experience' and move on. That’s the blind spot. The market will punish this, but not directly. Instead, liquidity providers will migrate to bridges with proven security models—Stargate’s LayerZero, Synapse’s oracle-backed design, or even native CCTP. The losers are the retail LPs who stayed out of loyalty. "Options don't predict the future; they price its uncertainty." The volatility premium for Allbridge will now be prohibitively high. And the stolen funds? Already mixed through Tornado Cash, vanishing into privacy’s dark pool. The team’s plea for the thief to 'return the funds' is a PR gesture, not a recovery plan.
When code repeats its own mistakes, it’s not an exploit—it’s a verdict. Allbridge’s pause button is a confession of failure. The question isn’t whether they’ll recover TVL; it’s whether the broader market will finally demand that cross-chain bridges treat pricing as a security issue, not a UX feature. Until then, every pool ratio is a honeypot waiting to be drained. "Terra’s code was poetry; Luna’s exit was prose." Allbridge’s code was prose. Its exit? A footnote.