In brief

Cross-chain bridge Allbridge paused its Core protocol on Sunday evening after what it called a security incident on its Solana deployment. The team's statement went out at 19:58 UTC on July 19; by early Monday UTC, security firms PeckShield and CertiK had flagged the incident and estimated the loss at roughly $1.65 million, with the funds bridged from Solana to Ethereum. Allbridge posted a return address, advised liquidity providers to withdraw, and said its goal is to return all affected funds. The team has not confirmed a total or explained the mechanism.

What happened

Allbridge said at 19:58 UTC on Sunday, July 19 that "Allbridge Core is experiencing a security incident" and that it had "paused the protocol as a precaution" while investigating. Its announcements channel repeated the notice at 20:37 UTC and advised liquidity providers to withdraw their positions. Allbridge Core is the project's cross-chain stablecoin transfer system; the incident, per the tracking accounts that followed it, centered on its Solana deployment.

Loss estimates evolved overnight. Onchain Lens put the figure at $1.1 million-plus at 00:29 UTC on July 20; PeckShield estimated roughly $1.65 million at 01:10 UTC and reported the funds had been bridged from Solana to Ethereum; CertiK published a Solana transaction hash and an Ethereum address associated with the exploiter; and Lookonchain reported the funds were swapped for ETH, linking explorer pages for addresses on both chains. CryptoBriefing, citing on-chain data flagged by Arkham Intelligence, reported the same movement pattern and a total of roughly $1.65 million. Allbridge has not confirmed a total.

The response, and a prior incident

Allbridge published an Ethereum return address alongside its statement and asked that funds taken during the incident be returned, saying compensation of liquidity providers is intended and, in a follow-up, that "our goal is to return all affected funds." The project used a similar response after an April 2023 flash-loan attack on its BNB Chain pools that caused about $573,000 in losses: it offered the attacker a bounty to come forward. Whether that approach produces a return here is unknown, and this report does not predict it.

The pause halts a protocol whose function is moving stablecoins between chains, so the practical impact extends to users with liquidity in Core pools — the group Allbridge specifically advised to withdraw.

What to watch

The concrete next signals: a technical post-mortem from Allbridge, an official loss figure, any movement on the return address or the exploiter's addresses, a timeline for unpausing the protocol, and the terms of any liquidity-provider compensation.

What we do not know

Allbridge has not described how the exploit worked; press accounts circulating a specific mechanism could not be bound to a capturable primary record at our cutoff, so no mechanism is asserted here. The exploiter has not been identified, and no attribution has been made by anyone in the reviewed record. The final loss figure remains a third-party estimate, the prospects for recovery are unknown, and the duration of the pause is unstated.

Sources

Observations from Allbridge — official incident statement (X, 19:58 UTC July 19), recorded .

Observations from Allbridge — follow-up on returning affected funds (X), recorded .

Observations from Allbridge — announcements channel statement (Telegram), recorded .

Observations from PeckShield — alert estimating ~$1.65 million (X), recorded .

Observations from Onchain Lens — earlier $1.1 million-plus estimate (X), recorded .

Observations from CertiK — alert with transaction hash and address (X), recorded .

Observations from Lookonchain — cross-chain movement of the funds (X), recorded .

Observations from CryptoBriefing — report citing Arkham Intelligence data, recorded .

Observations from Cointelegraph — April 2023 Allbridge flash-loan incident (context), recorded .

More market news →

Sources & notes

For readers who want the detail, these are the notes and source links attached to this edition.

StatementTypeBasisEvidence
Allbridge said at 19:58 UTC on July 19, 2026 that Allbridge Core was experiencing a security incident and that the protocol had been paused as a precaution while the team investigates.reported eventreportedevidence:allbridge-statement-x-0720, evidence:allbridge-telegram-0720
Allbridge's announcements channel repeated the notice at 20:37 UTC and advised liquidity providers to withdraw their positions.reported factreportedevidence:allbridge-telegram-0720
Loss estimates evolved overnight: Onchain Lens put the figure at $1.1 million-plus at 00:29 UTC on July 20, and PeckShield estimated roughly $1.65 million at 01:10 UTC; Allbridge has not confirmed a total.reported factreportedevidence:onchainlens-x-0720, evidence:peckshield-alert-x-0720
PeckShield and Lookonchain reported that the funds were bridged from Solana to Ethereum, with Lookonchain adding that they were swapped for ETH.reported factreportedevidence:peckshield-alert-x-0720, evidence:lookonchain-x-0720
CertiK published a Solana transaction hash and an Ethereum address associated with the exploiter, and Lookonchain linked explorer pages for addresses on both chains.reported factreportedevidence:certik-alert-x-0720, evidence:lookonchain-x-0720
CryptoBriefing, citing on-chain data flagged by Arkham Intelligence, likewise described the attacker extracting funds from Allbridge's infrastructure and moving them across networks, with the reported total settling around $1.65 million.reported factreportedevidence:cryptobriefing-allbridge-0720
Allbridge published an Ethereum return address, asked that funds taken during the incident be returned, and said its goal is to return all affected funds to users.reported factreportedevidence:allbridge-statement-x-0720, evidence:allbridge-reply-x-0720, evidence:allbridge-telegram-0720
In April 2023, Allbridge lost about $573,000 in a flash-loan attack on its BNB Chain pools and offered the attacker a bounty to come forward.reported factreportedevidence:cointelegraph-allbridge-2023
Allbridge has not published a technical description of how the exploit worked, has not confirmed a total loss, and has not said when the protocol will resume; the exploiter has not been identified in any record reviewed at the cutoff.reported factreportedevidence:allbridge-statement-x-0720, evidence:allbridge-telegram-0720

Stay informed

Weekly Lens

Get one evidence-led market briefing each week: what changed, what the data supports and what remains uncertain. Free to read, no spam, unsubscribe any time.

Crypto Market Lens is free. We store only what you enter here, never sell it, and you can unsubscribe any time.