USDT live
Supply 112.4B +0.8%
Tron share 53.2%
ETH share 38.4%
TRC20 gas $0.95 -2.1%
ERC20 gas $4.20
24h volume $48.2B
English · 中文

Allbridge Core Suspends Protocol After $1.65M Flash Loan Attack: Real-World Impact on Cross-Chain U-Card Top-Ups

2026-07-21

Cross-chain stablecoin bridge Allbridge Core has suspended its protocol operations after a flash loan attack. According to on-chain security firms PeckShield and CertiK, attackers stole approximately $1.65M and have already moved the stolen funds from Solana to Ethereum via bridging. The incident was reported by The Block on July 20, and the Allbridge team subsequently shut down the protocol proactively to limit further losses. One clarification: the specific claim that “funds were bridged to Ethereum” comes from on-chain tagging by security firms — we have not conducted independent on-chain verification, and readers can follow further disclosures via PeckShield’s official channels.

Editorial Take: What Does This Have to Do With Your U-Card

Let’s be clear upfront: Allbridge is a cross-chain bridge protocol, not a card issuer. The top-up path for most mainstream USDT virtual cards runs through internal exchange transfers or direct on-chain top-ups to an address designated by the issuer — there’s no direct dependency on Allbridge. So if you’re worried “will the money on my card get stolen” — the answer is generally no, unless you happened to have funds parked in Allbridge’s liquidity pool during the attack window.

What’s actually affected is a specific habit: moving funds from one chain to another, then topping up a card. For example, if you hold USDC on Solana and want to fund a card that only accepts USDT on Ethereum or Tron, a bridge comes into play. Users in this category should keep the following in mind over the coming window:

If you’re still shopping for a card, check out our MPCard review — its Asia Elite variant is built around an Asia-Pacific virtual Visa route; refer to its official page for specific top-up path details. To compare overall performance side by side, our 2026 Top 5 U-Cards list also notes each card’s top-up method differences.

Historical Comparison: Cross-Chain Bridges Have Always Been a Prime Attack Target

Bridge exploits aren’t new — they’re one of the most concentrated categories of incidents in crypto security over the past several years. Compared to previous major cases, this Allbridge incident is actually on the smaller side:

IncidentDateLossSource
Wormhole2022~$326MWormhole official statement
Ronin Bridge2022~$625MRonin official blog
Allbridge Core2026~$1.65MThe Block

Similarities: In each case, a cross-chain bridge — a centralized custody point for funds — was breached, and the stolen funds were quickly dispersed across chains to evade tracking. Allbridge’s move from Solana to Ethereum follows the same laundering playbook seen in the Wormhole and Ronin cases.

Differences: First, the scale differs by two orders of magnitude — $1.65M is a minor case compared to the hundreds of millions in earlier incidents. Second, this attack exploited a flash loan — a DeFi-specific attack surface (borrowing a huge sum within a single transaction to manipulate protocol state) — whereas the Ronin case involved stolen private keys and Wormhole involved a signature verification flaw. These are fundamentally different attack types. The historical figures above are all sourced from each project’s official channels; exact amounts may be revised by the official sources as recovery efforts progress, so please refer to the source pages for the latest figures.

For ordinary U-card users, the takeaway from this comparison is: the less you depend on cross-chain bridges, the safer your funds are. This isn’t a question of “which bridge is more trustworthy” — it’s “avoid the bridge altogether whenever you can.”

Compliance and Security Perspective: The Bridge Isn’t the Issuer, But Regulators Are Watching the Same Thing

Cross-chain bridges currently remain in a regulatory gray zone in most jurisdictions — they are neither licensed payment institutions nor subject to traditional financial custody rules. If a bridge is breached, users have almost no legal recourse. This differs from a card issuer’s position: compliant issuers are typically bound by local payment/EMI licensing requirements, with clear rules on fund segregation.

If you’re choosing a card from a compliance standpoint, rather than fixating on cross-chain bridges, it’s more productive to first confirm the issuer’s own licensing status. In our EU compliance guide, we outline the requirements for licensed EMIs under the MiCAR framework, and our Hong Kong compliance guide explains local regulators’ stance on stablecoin-related services. The clear boundary is this: cross-chain bridges themselves are, in most regions, neither explicitly prohibited nor brought into a licensing regime — they fall into a “use at your own risk” gray zone — whereas an issuer’s payment business is subject to clear licensing requirements.

Key Developments Worth Watching Next

Editorial Recommendations

Every cross-chain bridge incident is a reminder of the same thing: the more intermediary steps involved, the more places things can go wrong. Keeping this principle in mind when choosing a card is more useful than asking “which bridge is safe.”