Flash Loan Exploit Targets DeFi Protocol on Solana, Resulting in Seven-Figure Loss

On July 20th, the cross-chain bridging protocol Allbridge Core fell victim to a sophisticated attack on the Solana blockchain. Onchain Lens monitoring data reveals the exploit resulted in a loss exceeding $1.1 million, highlighting persistent vulnerabilities within DeFi liquidity pool mechanisms.

Step-by-Step Breakdown of the Attack Vector

The attack leveraged the instant capital access of flash loans combined with precise market manipulation, executed within a single transaction block.

  • Step 1: Flash Loan Initiation The attacker initiated a flash loan from the Kamino protocol, borrowing 1.12 million USDC to seed the attack.
  • Step 2: Price Manipulation A series of rapid, large-volume USDC/USDT swap transactions was executed to artificially skew the exchange rate within Allbridge's stablecoin liquidity pool.
  • Step 3: Liquidity Exploitation Capitalizing on the temporary price discrepancy, the attacker withdrew substantial liquidity from the pool at the manipulated, favorable rate.
  • Step 4: Loan Repayment & Profit Within the same transaction, the flash loan was repaid using the proceeds, completing a zero-capital attack and securing a net profit.

The attacker's final gain was approximately $1.1 million. On-chain data indicates the funds were moved shortly after the exploit. Notably, the attack involved a single withdrawal of up to $2.24 million in USDC, demonstrating the severe impact when such vulnerabilities are exploited.

Broader Implications for DeFi Security

This incident underscores a critical challenge in the highly composable DeFi ecosystem: the potent combination of flash loans and delicate liquidity pool economics. It serves as a stark reminder for protocols to implement rigorous audits of their pricing oracles and pool mechanics, and to consider safeguards against instantaneous, high-volume transactions that can destabilize core protocol functions.