← Allbridge Core Second Flash-Loan Exploit (July 2026)1 decision on this page
Audit log
Every state-changing event for Allbridge Core Second Flash-Loan Exploit (July 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-02 23:28:25ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
14cReAhtudv1…6tP33ubasha256 → base58
verifying row…canonical bytes (25688 B) ▸
{"actor":"system:backfill","investigation_id":"f74f4088-dfe6-458b-8b9f-d6ac9d197312","kind":"publish","page_slug":"allbridge-core-second-flash-loan-exploit-july-2026","published_at":"2026-08-02T23:28:25.293Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Allbridge Core Second Flash-Loan Exploit (July 2026)","sections":[{"content":"On July 19, 2026 at approximately 17:51 UTC, Allbridge Core's Solana stablecoin liquidity pools were drained of approximately $1.65–1.66 million in a flash-loan exploit. The protocol paused all pool-based operations within 25 minutes of detecting the incident. PeckShield and CertiK independently corroborated the loss estimate. Allbridge Core is a cross-chain bridge that routes native stablecoins (USDC, USDT) across blockchains without issuing wrapped assets, and at the time of the exploit managed approximately 890,000 wallets and a TVL near $21.61 million. Following the exploit, TVL dropped sharply to approximately $12.78 million as liquidity providers withdrew during the uncertainty.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":1,"name":"Allbridge Core pauses protocol after $1.65 million flash loan exploit — The Block","type":"news_article","url":"https://www.theblock.co/post/408855/allbridge-core-exploit"},{"credibility":1,"name":"Cross-chain protocol Allbridge halts after $1.65 million flash loan exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/20/cross-chain-protocol-allbridge-halts-after-usd1-65-million-flash-loan-exploit"},{"credibility":2,"name":"Allbridge Core Pauses Bridge After $1.66M Solana Flash Loan Exploit — NFTEvening","type":"news_article","url":"https://nftevening.com/allbridge-core-pauses-bridge-after-1-66m-solana-flash-loan-exploit/"},{"credibility":2,"name":"Allbridge Flash Loan Attack Drains $1.65M — For the Second Time — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/20/allbridge-flash-loan-attack/"}]},{"content":"The exploit followed a nine-step pool manipulation sequence. The attacker initiated a flash loan of approximately $1.12 million USDC from Kamino Finance on Solana. They then executed repeated alternating USDC-to-USDT swaps through Allbridge Core's stablecoin pool, artificially pushing the pool's internal ratio away from its 1:1 stablecoin parity. This distortion allowed the attacker to withdraw liquidity at the manipulated, favorable exchange rates — on-chain data shows approximately 948,927.53 USDT was withdrawn and $2.24 million USDC was moved across the bridge. The attacker then repaid the Kamino flash loan within the same atomic transaction and retained the net difference as profit. Post-exploit forensic analysis identified three specific defense failures: dynamic fees remained static and did not scale with manipulation velocity; TWAP (time-weighted average price) guards were absent; and circuit breakers failed to trigger despite the pool ratio deviation exceeding normal thresholds. The nine-step manipulation sequence outpaced the Rebalancer Authority's reaction speed.","heading":"Attack Mechanics","severity":"critical","sources":[{"credibility":2,"name":"Allbridge Flash-Loan Exploit: How Pool Manipulation Drained $1.65 Million — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/07/allbridge-flash-loan-exploit-pool-manipulation"},{"credibility":2,"name":"Allbridge Core Pauses Bridge After $1.66M Solana Flash Loan Exploit — NFTEvening","type":"news_article","url":"https://nftevening.com/allbridge-core-pauses-bridge-after-1-66m-solana-flash-loan-exploit/"},{"credibility":2,"name":"Allbridge exploit: Flash loans still haunt DeFi — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/allbridge-exploit-flash-loans-still-haunt-defi-1-65m-drained-via-usdc-usdt-pool/"}]},{"content":"On-chain analysts, including CertiKAlert and Crypto Patel, publicly identified two attacker addresses: Solana wallet FhffBraZsGn4H2LxLNToEcaHWEfWwT2UcSz4oRHb7Qdc and Ethereum consolidation address 0x651591b68A9c9650FB23F642162353306281ffDe. Stolen assets were bridged from Solana to the Ethereum address immediately after the exploit, where they were converted to ETH. Allbridge and forensic partners traced approximately $1.63 million of the $1.65–1.66 million total. Portions of the funds were subsequently routed through privacy protocols including Railgun, NEAR Intents, and Zcash Orchard in an attempt to obfuscate the trail. On-chain analyst Hupzy described the cross-chain movement as a common money-laundering tactic that can make recovery significantly more difficult. No funds had been publicly confirmed returned as of reporting.","heading":"Fund Movements and Attacker Addresses","severity":"critical","sources":[{"credibility":3,"name":"Crypto Patel on X — attacker wallet addresses identified","type":"social_media","url":"https://x.com/CryptoPatel/status/2079106282083205557"},{"credibility":3,"name":"CertiK Alert on X","type":"social_media","url":"https://x.com/CertiKAlert/status/2079013163014770987"},{"credibility":2,"name":"Allbridge Core Hit by $1.65M Solana Exploit, Funds Traced to Ethereum — Coinpedia","type":"news_article","url":"https://coinpedia.org/news/allbridge-core-hit-by-1-65m-solana-exploit-funds-traced-to-ethereum/"},{"credibility":2,"name":"Allbridge Core Pauses Bridge After $1.66M Solana Flash Loan Exploit — NFTEvening","type":"news_article","url":"https://nftevening.com/allbridge-core-pauses-bridge-after-1-66m-solana-flash-loan-exploit/"}]},{"content":"In April 2023, Allbridge Core suffered its first flash-loan exploit, draining approximately $570,000–$573,000 from its BNB Chain stablecoin pools. The attacker in the 2023 incident acted as both liquidity provider and swapper, exploiting a flaw in the withdraw function's swap price calculation to extract approximately $289,900 in BUSD and $290,900 in USDT. The project later recovered roughly $465,000 after offering the attacker a white-hat bounty. Following the 2023 incident, the Allbridge team published a postmortem committing to a specific architectural remediation: the protocol would deploy only a single liquidity pool per blockchain, which it stated would make same-transaction flash loan manipulation 'structurally impossible.' The team also introduced the 'Rebalancer Authority' — a special administrative account capable of rebalancing pools across chains without paying fees — as well as automatic pool suspension mechanisms triggered by imbalance thresholds. Despite these stated fixes, the July 2026 attack succeeded because Allbridge's Solana deployment retained a pool architecture holding both USDC and USDT together, exactly the configuration the post-2023 fix was intended to eliminate. The TechTimes headline characterized this gap directly: 'Allbridge Core Loses $1.65M to Flash Loan Again After Its Single-Pool Fix Missed Solana.' No public explanation has been provided by Allbridge as to why the Solana deployment was excluded from the single-pool architectural fix applied after 2023.","heading":"Prior 2023 Exploit and Failed Remediation","severity":"critical","sources":[{"credibility":2,"name":"Allbridge Core Loses $1.65M to Flash Loan Again After Its Single-Pool Fix Missed Solana — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/321044/20260720/allbridge-core-loses-165m-flash-loan-again-after-its-single-pool-fix-missed-solana.htm"},{"credibility":2,"name":"Allbridge Core Hit by $1.65M Solana Flash-Loan Exploit, Its Second Since 2023 — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/20/allbridge-core-hit-by-1-65m-solana-flash-loan-exploit-its-second-since-2023/"},{"credibility":2,"name":"Decoding AllBridge $570K Flash Loan Exploit — QuillAudits / Coinmonks","type":"research","url":"https://medium.com/coinmonks/decoding-allbridge-570k-flash-loan-exploit-quillaudits-8da8dccd729d"},{"credibility":2,"name":"Allbridge Core Updates Following the Relaunch — Allbridge Medium","type":"official","url":"https://allbridge.medium.com/allbridge-core-updates-following-the-relaunch-9f7716eeb5da"}]},{"content":"Allbridge has undergone at least five security audits prior to the July 2026 exploit: by Hacken in September 2021, by Kudelski Security in May 2022, by Cossack Labs in September 2022, by Hacken again in February 2022, and by CoinFabrik in July 2023 (post-first-exploit). Halborn additionally conducted a security assessment of Allbridge's Bridge and ERC20 contracts beginning June 17, 2024 and concluding July 17, 2024. The frequency of audits did not prevent a repeated exploit using a structurally similar vector. Notably, the post-2023 Medium post from Allbridge indicated that Solana contract verification would be added to the public GitHub repository pending 'internal tests,' suggesting the Solana deployment may have received less scrutiny than other chains at the time the single-pool fix was implemented.","heading":"Security Audit History","severity":"high","sources":[{"credibility":2,"name":"AllBridge Audit Report — CoinFabrik","type":"research","url":"https://www.coinfabrik.com/blog/allbridge-audit-report/"},{"credibility":2,"name":"Bridge Contracts Audit — Halborn","type":"research","url":"https://www.halborn.com/audits/casper-association/casper---allbridge-fa8c33"},{"credibility":2,"name":"Smart contract security audit for Allbridge Classic — Cossack Labs","type":"research","url":"https://www.cossacklabs.com/case-studies/smart-contract-security-audit-for-allbridge-cross-chain-bridge-with-tezos/"},{"credibility":2,"name":"Allbridge Core Updates Following the Relaunch — Allbridge Medium","type":"official","url":"https://allbridge.medium.com/allbridge-core-updates-following-the-relaunch-9f7716eeb5da"}]},{"content":"Allbridge paused its Core protocol within approximately 25 minutes of detecting the exploit. The team issued a public statement acknowledging a 'security incident' and urged all liquidity providers to withdraw from affected pools immediately. The team also made a public appeal directed at traders who had profited from the resulting price imbalance — a group distinct from the primary attacker — requesting voluntary return of funds to a designated recovery address, with stated intent to use any returned assets to compensate affected liquidity providers. Allbridge traced approximately $1.63 million of the stolen funds through Ethereum. Approximately $1.12 million in USDC was identified as having been extracted (1,118,239 USDC) alongside 538,692 USDT. No announcement of recovered funds was made during the reporting window. In response to the exploit, Allbridge announced a significant architectural shift: both Allbridge Core and Allbridge Classic would cease operating in their current pool-based form within three months of the incident. The planned successor architecture would route transactions entirely through CCTP (Circle's Cross-Chain Transfer Protocol) and LayerZero, eliminating liquidity pool dependency and the pool-imbalance attack surface entirely.","heading":"Protocol Response and Recovery Efforts","severity":"high","sources":[{"credibility":2,"name":"Allbridge Core Pauses Protocol After Attacker Drains More Than $1 Million — BeInCrypto","type":"news_article","url":"https://beincrypto.com/allbridge-core-solana-exploit-paused/"},{"credibility":2,"name":"Allbridge Core Pauses Bridge After $1.66M Solana Flash Loan Exploit — NFTEvening","type":"news_article","url":"https://nftevening.com/allbridge-core-pauses-bridge-after-1-66m-solana-flash-loan-exploit/"},{"credibility":2,"name":"Allbridge Core Pauses Protocol After $1.65 Million Exploit as Investigation Begins — Cryptometer","type":"news_article","url":"https://www.cryptometer.io/news/allbridge-core-pauses-protocol-after-1-65-million-exploit-as-investigation-begins/"},{"credibility":2,"name":"Allbridge Core Hit by $1.65M Solana Exploit, Funds Traced to Ethereum — Coinpedia","type":"news_article","url":"https://coinpedia.org/news/allbridge-core-hit-by-1-65m-solana-exploit-funds-traced-to-ethereum/"}]},{"content":"The Allbridge Core exploit occurred during a period of elevated cross-chain bridge attack frequency. CoinTelegraph noted the Allbridge incident was 'at least the sixth attack targeting a cross-chain bridge since May' 2026. The broader July 2026 landscape saw approximately $210.3 million lost across 30 major crypto hacks, a 177.2% increase from the prior month's $75.87 million, according to NullTX. Notable July 2026 incidents in the bridge category included the Wanchain and Verus bridge vulnerabilities (combined $20.5 million) and transit finance exploit ($1.88 million). Security commentators across multiple outlets emphasized that few of the July 2026 losses resulted from genuinely novel attack vectors — the majority exploited known, unaddressed vulnerability classes including single-source price feeds, inadequate circuit breakers, and flash-loan-susceptible pool pricing mechanisms — the same class that Allbridge had allegedly remediated in 2023.","heading":"Broader Industry Context: Cross-Chain Bridge Vulnerabilities in 2026","severity":"medium","sources":[{"credibility":1,"name":"Allbridge Core pauses cross-chain bridge after $1.65M exploit — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/allbridge-core-pauses-cross-chain-bridge-after-165m-exploit"},{"credibility":2,"name":"How July's $210M In Hacks Could Have Been Prevented — NullTX","type":"news_article","url":"https://nulltx.com/how-julys-210m-in-hacks-could-have-been-prevented"},{"credibility":2,"name":"Allbridge Core Exploit Pauses Cross-Chain Bridge After $1.65M Solana Attack — TronWeekly","type":"news_article","url":"https://www.tronweekly.com/allbridge-core-exploit-forces-bridge-pause/"}]},{"content":"The July 2026 Allbridge Core exploit raises several documented risk factors. First, the vulnerability pattern is a direct repetition of the April 2023 attack: the same flash-loan pool-manipulation vector was used against the same protocol class. Second, the post-2023 remediation was incomplete: the single-pool fix the team publicly committed to was not applied to the Solana deployment, a gap that went undetected across at least six audits conducted after the 2023 incident (including one by Halborn in mid-2024). Third, the Rebalancer Authority mechanism introduced after 2023 failed to outpace the nine-step manipulation sequence. Fourth, post-exploit fund movements through privacy protocols (Railgun, NEAR Intents, Zcash Orchard) reduced the likelihood of recovery. The protocol's announced exit from pool-based bridging — though a substantive architectural response — means that Allbridge Core in its current form is being wound down. Users with active liquidity positions in Allbridge Core should be aware of the ongoing protocol suspension and the announced three-month transition timeline. No law enforcement action or regulatory filing related to this incident has been identified as of the investigation date.","heading":"Risk Assessment","severity":"high","sources":[{"credibility":2,"name":"Allbridge Core Loses $1.65M to Flash Loan Again After Its Single-Pool Fix Missed Solana — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/321044/20260720/allbridge-core-loses-165m-flash-loan-again-after-its-single-pool-fix-missed-solana.htm"},{"credibility":2,"name":"Allbridge Core Pauses After $1.65M Flash-Loan Exploit — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/07/allbridge-core-pauses-flash-loan-exploit"},{"credibility":1,"name":"Allbridge Pauses Cross-Chain Protocol After $1.65M Flash Loan Attack — Decrypt","type":"news_article","url":"https://decrypt.co/373831/allbridge-pauses-cross-chain-protocol-after-1-65m-flash-loan-attack"}]}],"sources_used":[{"credibility":1,"name":"Cross-chain protocol Allbridge halts after $1.65 million flash loan exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/20/cross-chain-protocol-allbridge-halts-after-usd1-65-million-flash-loan-exploit"},{"credibility":1,"name":"Allbridge Core pauses protocol after $1.65 million flash loan exploit — The Block","type":"news_article","url":"https://www.theblock.co/post/408855/allbridge-core-exploit"},{"credibility":1,"name":"Allbridge pauses cross-chain bridge after $1.65M exploit — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/allbridge-core-pauses-cross-chain-bridge-after-165m-exploit"},{"credibility":1,"name":"Allbridge Pauses Cross-Chain Protocol After $1.65M Flash Loan Attack — Decrypt","type":"news_article","url":"https://decrypt.co/373831/allbridge-pauses-cross-chain-protocol-after-1-65m-flash-loan-attack"},{"credibility":2,"name":"Allbridge Flash Loan Attack Drains $1.65M — For the Second Time — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/20/allbridge-flash-loan-attack/"},{"credibility":2,"name":"Allbridge Core Loses $1.65M to Flash Loan Again After Its Single-Pool Fix Missed Solana — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/321044/20260720/allbridge-core-loses-165m-flash-loan-again-after-its-single-pool-fix-missed-solana.htm"},{"credibility":2,"name":"Allbridge Core Hit by $1.65M Solana Flash-Loan Exploit, Its Second Since 2023 — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/20/allbridge-core-hit-by-1-65m-solana-flash-loan-exploit-its-second-since-2023/"},{"credibility":2,"name":"Allbridge Core Hit by $1.65M Solana Exploit, Funds Traced to Ethereum — Coinpedia","type":"news_article","url":"https://coinpedia.org/news/allbridge-core-hit-by-1-65m-solana-exploit-funds-traced-to-ethereum/"},{"credibility":2,"name":"Allbridge Core halted after $1.65M Solana exploit — Crypto.news","type":"news_article","url":"https://crypto.news/allbridge-core-halted-after-1-65m-solana-exploit/"},{"credibility":2,"name":"Allbridge Core Pauses After $1.65M Flash-Loan Exploit — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/07/allbridge-core-pauses-flash-loan-exploit"},{"credibility":2,"name":"Allbridge Flash-Loan Exploit: How Pool Manipulation Drained $1.65 Million — CryptoDaily","type":"news_article","url":"https://cryptodaily.co.uk/2026/07/allbridge-flash-loan-exploit-pool-manipulation"},{"credibility":2,"name":"Allbridge Core Pauses Bridge After $1.66M Solana Flash Loan Exploit — NFTEvening","type":"news_article","url":"https://nftevening.com/allbridge-core-pauses-bridge-after-1-66m-solana-flash-loan-exploit/"},{"credibility":2,"name":"Allbridge Core Pauses Protocol After Attacker Drains More Than $1 Million — BeInCrypto","type":"news_article","url":"https://beincrypto.com/allbridge-core-solana-exploit-paused/"},{"credibility":2,"name":"Allbridge exploit: Flash loans still haunt DeFi — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/allbridge-exploit-flash-loans-still-haunt-defi-1-65m-drained-via-usdc-usdt-pool/"},{"credibility":2,"name":"Allbridge Core Exploit Pauses Cross-Chain Bridge After $1.65M Solana Attack — TronWeekly","type":"news_article","url":"https://www.tronweekly.com/allbridge-core-exploit-forces-bridge-pause/"},{"credibility":2,"name":"Allbridge Confirms Core Exploit, Losses Estimated Around $1.65M — Blockzeit","type":"news_article","url":"https://blockzeit.com/allbridge-core-exploit-losses-estimated-at-around-1-65m/"},{"credibility":2,"name":"Allbridge Core Updates Following the Relaunch — Allbridge Medium","type":"official","url":"https://allbridge.medium.com/allbridge-core-updates-following-the-relaunch-9f7716eeb5da"},{"credibility":2,"name":"Decoding AllBridge $570K Flash Loan Exploit — QuillAudits / Coinmonks","type":"research","url":"https://medium.com/coinmonks/decoding-allbridge-570k-flash-loan-exploit-quillaudits-8da8dccd729d"},{"credibility":2,"name":"AllBridge Audit Report — CoinFabrik","type":"research","url":"https://www.coinfabrik.com/blog/allbridge-audit-report/"},{"credibility":2,"name":"Bridge Contracts Audit — Halborn (Casper/Allbridge)","type":"research","url":"https://www.halborn.com/audits/casper-association/casper---allbridge-fa8c33"},{"credibility":2,"name":"Smart contract security audit for Allbridge Classic — Cossack Labs","type":"research","url":"https://www.cossacklabs.com/case-studies/smart-contract-security-audit-for-allbridge-cross-chain-bridge-with-tezos/"},{"credibility":2,"name":"How July's $210M In Hacks Could Have Been Prevented — NullTX","type":"news_article","url":"https://nulltx.com/how-julys-210m-in-hacks-could-have-been-prevented"},{"credibility":2,"name":"Allbridge Suspends Core Protocol After $1.65M Solana Flash Loan Exploit — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/605e8-allbridge-suspends-core-protocol-after-1-65m-solana-flash-loan-exploit"},{"credibility":3,"name":"Crypto Patel on X — attacker wallet addresses","type":"social_media","url":"https://x.com/CryptoPatel/status/2079106282083205557"},{"credibility":3,"name":"CertiK Alert on X — exploit alert","type":"social_media","url":"https://x.com/CertiKAlert/status/2079013163014770987"},{"credibility":2,"name":"DeFi Allbridge Urges Liquidity Providers to Withdraw Pool Funds in Latest Bridge Exploit — BitKE","type":"news_article","url":"https://bitcoinke.io/2026/07/the-allbridge-exploit/"},{"credibility":2,"name":"Hacker Exploits Allbridge Core, Draining $1,660,000 — Daily Hodl","type":"news_article","url":"https://dailyhodl.com/2026/07/21/hacker-exploits-allbridge-core-draining-1660000-worth-of-crypto-from-cross-chain-stablecoin-bridge/"}],"summary":"On July 19–20, 2026, Allbridge Core, a cross-chain stablecoin bridge protocol, suffered a $1.65–1.66 million flash-loan exploit targeting its Solana USDC/USDT liquidity pools — the second structurally similar attack on the protocol since April 2023. An attacker borrowed $1.12 million USDC from Kamino Finance, manipulated the pool's internal stablecoin ratio through rapid swaps, extracted liquidity at distorted rates, then bridged the proceeds to Ethereum before the protocol was paused. The incident raised serious questions about the completeness of post-2023 remediation, specifically the failure to apply the protocol's own 'single-pool per blockchain' fix to its Solana deployment.","timeline":[{"date":"2023-04-01","event":"Allbridge Core suffers its first flash-loan exploit on BNB Chain, draining approximately $573,000 in BUSD and USDT. Attacker acted as both liquidity provider and swapper to manipulate pool pricing.","source":"Decoding AllBridge $570K Flash Loan Exploit — QuillAudits / Coinmonks","source_url":"https://medium.com/coinmonks/decoding-allbridge-570k-flash-loan-exploit-quillaudits-8da8dccd729d"},{"date":"2023-05-01","event":"Allbridge publishes post-exploit postmortem committing to single-pool-per-blockchain architecture to prevent flash loan attacks, introduces Rebalancer Authority, and opens contracts on GitHub. Recovers approximately $465,000 via white-hat offer.","source":"Allbridge Core Updates Following the Relaunch — Allbridge Medium","source_url":"https://allbridge.medium.com/allbridge-core-updates-following-the-relaunch-9f7716eeb5da"},{"date":"2023-07-01","event":"CoinFabrik completes security audit of Allbridge.","source":"AllBridge Audit Report — CoinFabrik","source_url":"https://www.coinfabrik.com/blog/allbridge-audit-report/"},{"date":"2024-07-17","event":"Halborn completes security assessment of Allbridge Bridge and ERC20 contracts (engagement ran June 17 – July 17, 2024).","source":"Bridge Contracts Audit — Halborn","source_url":"https://www.halborn.com/audits/casper-association/casper---allbridge-fa8c33"},{"date":"2026-07-19","event":"At approximately 17:51 UTC, an attacker initiates a $1.12 million USDC flash loan from Kamino Finance on Solana and executes a nine-step pool manipulation against Allbridge Core's USDC/USDT stablecoin pool, draining approximately $1.65–1.66 million.","source":"Allbridge Core Pauses Bridge After $1.66M Solana Flash Loan Exploit — NFTEvening","source_url":"https://nftevening.com/allbridge-core-pauses-bridge-after-1-66m-solana-flash-loan-exploit/"},{"date":"2026-07-19","event":"Allbridge Core protocol is paused within approximately 25 minutes of the exploit. Stolen funds are bridged from Solana wallet FhffBraZsGn4H2LxLNToEcaHWEfWwT2UcSz4oRHb7Qdc to Ethereum address 0x651591b68A9c9650FB23F642162353306281ffDe, converted to ETH, and routed through Railgun, NEAR Intents, and Zcash Orchard.","source":"Crypto Patel on X — attacker wallet addresses","source_url":"https://x.com/CryptoPatel/status/2079106282083205557"},{"date":"2026-07-20","event":"Allbridge issues public statement confirming the security incident, urging LP withdrawals, appealing to arbitrageurs to voluntarily return profits, and announcing that Core and Allbridge Classic will cease pool-based operations within three months in favor of CCTP and LayerZero routing.","source":"Cross-chain protocol Allbridge halts after $1.65 million flash loan exploit — CoinDesk","source_url":"https://www.coindesk.com/business/2026/07/20/cross-chain-protocol-allbridge-halts-after-usd1-65-million-flash-loan-exploit"},{"date":"2026-07-20","event":"Allbridge reports tracing approximately $1.63 million of the stolen funds. No recovery of assets is confirmed. TVL of Allbridge Core falls from approximately $21.61 million to $12.78 million.","source":"Allbridge Core Hit by $1.65M Solana Exploit, Funds Traced to Ethereum — Coinpedia","source_url":"https://coinpedia.org/news/allbridge-core-hit-by-1-65m-solana-exploit-funds-traced-to-ethereum/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 523a0099-88d1-4015-98e8-f6425bdd0dc3
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.