Cross-chain routing protocol Allbridge has temporarily halted its bridging operations after suffering a smart contract exploit that drained approximately $1.65 million from its BNB Chain liquidity pool. The team detected the anomalous transactions early on July 20, 2026, and moved quickly to pause the bridge to safeguard remaining assets across other supported networks.
How did the Allbridge exploit occur?
According to onchain data, the attacker targeted the BUSD/USDT pool on BNB Chain using a flash loan-assisted price manipulation vector. By borrowing a substantial amount of capital, the exploiters artificially skewed the ratio of the liquidity pool, manipulating the protocol's internal formula for calculating swap rates and pool share values. This allowed the attacker to deposit a small amount of liquidity and withdraw a disproportionately large payout, effectively draining the pool's reserves.
“The vulnerability stemmed from an imbalance in how the pool calculated its virtual price during highly volatile, single-sided swaps,” says Marcus Vance, lead smart contract auditor at CertiShield. “By manipulating the pool's state before withdrawing, the attacker convinced the smart contract that their share of the pool was worth significantly more than its actual value.”
The table below outlines the structural impact of the exploit on the protocol's primary BNB Chain pool:
| Metric | Pre-Exploit State | Post-Exploit State (Paused) |
|---|---|---|
| BNB Chain Pool TVL | ~$2.10 Million | ~$450,000 |
| Bridge Status | Active (Multi-chain) | Suspended (All chains) |
| Estimated Loss | $0 | $1.65 Million (BUSD/USDT) |
| Primary Vulnerability | None identified | Virtual price manipulation formula |
What is the immediate recovery plan for affected users?
Allbridge has announced that it is actively working with security firms and onchain analytics platforms to trace the stolen funds, which have already been moved through several decentralized mixers. The protocol has issued an onchain message to the attacker's wallet address, offering a 10% white-hat bounty in exchange for the return of the remaining 90% of the funds, promising no legal action if the terms are met.
For liquidity providers and bridge users, the team has stated that a comprehensive compensation plan is being drafted. Because the bridge contracts are paused, user funds on non-affected chains remain secure but locked until the smart contracts are patched, audited, and redeployed. The incident highlights the persistent structural vulnerabilities of cross-chain liquidity designs, which remain a primary target for sophisticated DeFi exploits.