USDT live
Supply 112.4B +0.8%
Tron share 53.2%
ETH share 38.4%
TRC20 gas $0.95 -2.1%
ERC20 gas $4.20
24h volume $48.2B
English · 中文

Allbridge Core Loses $1.65M in Flash Loan Attack, Cross-Chain Stablecoin Bridge Vulnerability Resurfaces

2026-07-21

The cross-chain stablecoin protocol Allbridge Core suffered a flash loan attack on its Solana liquidity pool, losing roughly $1.65 million (approximately 2.445 billion South Korean won), and the protocol has since suspended service. According to a Tokenpost report, analysis from security firms CertiK and PeckShield shows the attacker first borrowed a flash loan of about $1.12 million from Solana lending protocol Kamino, then repeatedly swapped within Allbridge’s USDC/USDT pool to artificially distort the ratio between the two stablecoins, ultimately extracting arbitrage profit before exiting. A flash loan is a mechanism that completes “borrow—act—repay” within a single transaction, allowing large sums to be moved without collateral — which is exactly why it keeps getting used as a weapon for DeFi price manipulation.

Editorial Take: How Much Does This Affect the USDT Card in Your Pocket

The bottom line first: if you use a custodial USDT card, this incident essentially has no impact on your deposits or spending. What got attacked was a liquidity pool belonging to a decentralized cross-chain bridge like Allbridge — not an issuer’s custodial wallet.

Two deposit paths need to be distinguished:

For the vast majority of users who simply want a USDT card to pay for ChatGPT, Claude, or cloud service subscriptions, there will be zero noticeable impact within 7 days; within 30 days, you might see cross-chain bridge protocols briefly tighten withdrawals or increase audit frequency; within 90 days, what’s actually worth watching is whether this kind of vulnerability pushes exchanges to tighten “source of funds” scrutiny. If you’re planning to open a new card, check the deposit path details in the MPCard review first, and avoid leaving large sums parked at any point along the chain.

Historical Comparison: Flash Loan Price Manipulation Is Not a New Script

The flash loan attack playbook repeats itself almost every year, following a highly consistent pattern — borrow a large sum → distort a pool’s quoted price → arbitrage at the distorted price → repay the principal within a single transaction.

The common thread: all exploited the vulnerability of pool-based pricing mechanisms that can be instantly manipulated in an uncollateralized, atomic transaction. The difference: this one targeted a cross-chain stablecoin bridge — a structure that handles both USDC and USDT simultaneously and must maintain ratio parity across chains, which is inherently more fragile than a single-chain, single-asset pool. It should be noted that the figures cited in this article — $1.65 million, the $1.12 million flash loan, etc. — are all drawn from the above Tokenpost report’s summary of CertiK and PeckShield’s analysis; refer to the formal post-incident reports from both security firms for on-chain details.

Compliance Perspective: Bridge Theft and Card Source-of-Funds Screening

From a compliance standpoint, the indirect impact of incidents like this deserves more attention than the direct impact. After a cross-chain bridge is drained, stolen funds are typically split, mixed, and moved across chains, eventually potentially flowing into exchanges or card issuance channels. This raises sensitivity around “source of funds” across the entire pipeline.

Users in the Asia-Pacific region should pay particular attention to differences in local attitudes toward crypto asset transfers. Japan’s regulatory stance on stablecoins and fund flows is relatively clear — see the Japan compliance guide; Hong Kong has been gradually tightening under its licensed-exchange framework — see the Hong Kong compliance guide. The current boundaries roughly are:

Key Milestones Worth Watching Next

  1. Allbridge’s official post-mortem announcement — when the protocol resumes service, whether it will compensate affected users, and whether it will modify its pool pricing mechanism. Watch Allbridge’s official website and its official channels.
  2. Formal incident reports from CertiK / PeckShield — both firms will publish complete analyses with on-chain addresses, at which point the flow of the $1.65 million can be verified directly on Solscan.
  3. Movement of stolen funds — the 30 days following a flash loan attack are peak laundering period, which could trigger bulk risk-control actions against related addresses on the exchange side.
  4. Chain reactions among similar bridges — once one bridge is hit, cross-chain stablecoin bridges with similar architecture are usually found to have comparable vulnerabilities within weeks.

Editorial Recommendations

A cross-chain bridge is always the segment of the stablecoin ecosystem with the largest attack surface — treating it as a “passageway” rather than a “parking lot” is the same reminder these kinds of news stories keep delivering.