← Radar

Incident case file

Sign in to watch

Allbridge Core — Kamino flash loan stablecoin pool manipulation

Incident date July 19, 2026

1 views

PausedSolana → EthereumFlash Loan / Price ManipulationCluster: ALLBRIDGE-FLASHLOAN-2026-07

Estimated loss

$1.6M

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: Solana wallet (labeled 'Allbridge Exploiter 1' by Lookonchain/Solscan): FhffBraZsGn4H2LxLNToEcaHWEfWwT2UcSz4oRHb7Qdc | Ethereum destination: 0x651591b68A9c9650FB23F642162353306281ffDe

Funds moved to: ~$1.65M stolen via Kamino flash loan (~$1.12M USDC) + rapid USDC/USDT pool ratio manipulation on Allbridge Core Solana pools | Flash loan tx (Solana): 3LNLaGi36bqoSBFBqcQ3ZvDbnGCxrxu4rqahZrnfHZjKSYxfR1mqiCXtBXjjeBmoRQDeSiKxZ7c1nFb8pBgTY39Q | Funds bridged from Solana to Ethereum (0x651591b68A9c9650FB23F642162353306281ffDe) → laundered via Maya Protocol / MayaChain in batches of 7–44 ETH (still in progress as of July 28, 2026). Allbridge asked arbitrageurs who profited from the rate imbalance
Pre-attack gas funder (Solana): D8cJRpXaCWVK8c3doDq7Ymoz2XE4WyhFhbgNytWwqptA (~8 days before exploit) | Arbitrageur return address (ETH): 0x01a494079DCB715f622340301463cE50cd69A4D0 | Attack mechanism: flash loan of $1.12M USDC from Kamino → rapid USDC↔USDT swaps distorting the Allbridge Core USDC/USDT Solana pool internal exchange rate → withdraw liquidity at manipulated rate → repay flash loan in same transaction. Second flash-loan exploit of same class against Allbridge (first: 2023 BN

Timeline: On July 19, 2026, an attacker executed a flash loan attack against Allbridge Core's Solana stablecoin pools, draining approximately $1.65M. Using a Kamino flash loan of ~$1.12M USDC, the attacker performed rapid USDC↔USDT swaps to distort the pool's internal exchange rate, then withdrew liquidity at the manipulated rate before repaying the flash loan within the same transaction. The stolen funds were bridged from Solana to Ethereum destination wallet 0x651591b68A9c9650FB23F642162353306281ffDe. Allbridge immediately paused the Core protocol and urged LPs in affected pools to withdraw. The team asked traders who profited from the arbitrage imbalance to return funds to recovery address 0x01a494079DCB715f622340301463cE50cd69A4D0 for LP compensation. This was Allbridge Core's second flash-loan exploit — the same attack class as a 2023 BNB Chain incident (~$573K). Subsequent on-chain analysis (Arkham Intelligence) showed stolen funds being laundered via Maya Protocol/MayaChain in batches of 7–44 ETH, a process still ongoing as of July 28, 2026.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)