Allbridge Core paused its cross-chain stablecoin protocol on July 19 after an attacker drained its Solana-based USDC/USDT pool. PeckShield put the total at roughly $1.65 million; on-chain analysts pegged the single largest withdrawal closer to $2.24 million gross, before the attacker repaid the loan that funded the whole thing. Allbridge's own notice named the mechanics in the broadest strokes and asked anyone who'd profited from the resulting price imbalance to send funds back voluntarily. It did not publish a wallet-by-wallet trace.
I did.
Short version: The attacker flash-borrowed $1.12M in USDC from Kamino, used it to distort the ratio inside Allbridge Core's stablecoin pool via rapid swaps on two different Solana DEXs, then withdrew liquidity at the skewed rate and repaid the loan in the same transaction — a textbook flash-loan price manipulation. Three withdrawals came out the other side. One — 537,263.392903 USDC — moved into a Mayan Fast MCTP bridge transfer that's still sitting unsigned and unclaimed. The other two both ended up swapped to DAI and shielded into RAILGUN, independently, through two different wallets — with part of the third leg also forwarded toward a NEAR Protocol hot wallet, and roughly $300K still sitting untouched.
The Exploit in One Breath
According to on-chain analysts Onchain Lens and DBCrypto, the attack needed no leaked key and no bridge-level bug — just Allbridge Core's stablecoin pool trusting its own manipulable internal balance to price a swap. The sequence: flash-borrow $1.12M in USDC from Kamino with no collateral, use the borrowed capital to push the USDC/USDT ratio inside the pool off balance through rapid trading, withdraw liquidity at the now-distorted rate, repay the flash loan within the same transaction, and keep the difference. Simple in outline, expensive in practice.
Allbridge paused the protocol immediately afterward, told liquidity providers in affected pools to withdraw, and asked traders who'd caught a piece of the resulting arbitrage window to consider returning it to a recovery address. No technical post-mortem was published alongside that notice — which is where this picks up.
Watching the Attacker Wallet Move
The attacker's address on Solana: FhffBraZsGn4H2LxLNToEcaHWEfWwT2UcSz4oRHb7Qdc.
The on-chain sequence, in order: three transfers of exactly 100,000 (USDC) each, sent to Allbridge Core's pool authority. Then, in the same block, a pair of round-trip swaps — one through SolFiV2's USDT-USDC market (+316,983.581553 USDC in, -317,192.916382 out) and one through a Manifest USDT-USDC pool (+166,551.98754 USDC in, -166,660.684877 out) — the rapid back-and-forth trading that public reporting says moved the pool's internal price. Immediately after, the withdrawals started.
Three outbound transfers, all within minutes of each other:
537,263.392903 USDC → AXShwCCJ...WANNVQ52
558,560.163077 USDC → 6F6jESpn...2djavmMs
558,001.043795 USDC → 3eLkuaFg...BsrKvfQr
The First Leg: Stuck Mid-Bridge
537,263.392903 USDC went to AXShwCCJ...WANNVQ52. From there it moved into a Mayan Fast MCTP transfer bridging out of Solana toward Ethereum via Circle's CCTP — and that transfer is still sitting in pending claim: unsigned, waiting for someone to submit the claim step on the Ethereum side.
As of writing, that transfer hasn't been claimed — meaning a chunk of the Allbridge exploit proceeds is currently parked mid-bridge, waiting on a manual step that hasn't happened. Worth watching for when — and if — it does.
The Second Leg: Straight Into RAILGUN
The second withdrawal — 558,560.163077 USDC to 6F6jESpn...2djavmMs — moves fast once you follow it. It reaches 0x97bc883FF48b0A40Ee55dC5a9Ff731F18B52ea2D on Ethereum, and that wallet's very next move is a shield transaction into RAILGUN, a zero-knowledge privacy protocol for Ethereum. One transaction (0xcf97bb5901dfbf2dca8bf3c2ddcf7e9d85e26b45f13ef074b815d3e5d3571e34), two outputs: 769.43552398 DAI to RAILGUN's treasury (the protocol fee for shielding) and 307,004.77406901 DAI to RAILGUN's relay contract — the actual amount that just went shielded.
That's the second real trail-break in this piece. RAILGUN works the same way Tornado Cash and Zcash's shielded pools do: zero-knowledge proofs sever the on-chain link between what goes in and what comes out. No amount of clever querying gets past that math. What I can say for certain is what happened right up to the shield transaction — the amount, the fee split, the timing. What happens after is, by design, invisible.
The Third Leg: Split Three Ways
The third withdrawal — 558,001.043795 USDC — went through a swap-bridge widget and came out the other side as 557,774.209343 DAI on Ethereum, landing at 0x651591b68A9c9650FB23F642162353306281ffDe. The whole hop took 29 seconds, start to finish.
That destination wallet is worth a second look on its own. Before it ever touched the exploit funds, it had already been funded — through RAILGUN: Relay Adapt. Using RAILGUN's relay adapter to fund a fresh wallet is the same opsec move as funding gas through a service like Wagyu: it puts a privacy layer between the wallet and whatever paid for it, so the funding trail doesn't lead anywhere useful.
From there, the DAI split three ways. Part of it moved on through a two-hop forwarding pattern:
250,000 DAI: 0x651591b6...06281ffDe → 0x8fef26dC...FD1EA0234 → 0x2CfF890f...a2c302680
6,000 DAI: 0x651591b6...06281ffDe → 0x8fef26dC...FD1EA0234 → 0x2CfF890f...a2c302680
0x2CfF890f...a2c302680 is labeled as a NEAR Protocol hot wallet — meaning 256,000 of the 557,774 DAI has already moved off Ethereum entirely and onto NEAR, an ecosystem most standard EVM screening tools don't follow. A further slice went the other direction entirely, back into RAILGUN's shielded pool — the same protocol the second leg used. Roughly $300,240 remains untouched at 0x651591b6...06281ffDe itself, sitting there since the last forwarding transaction five hours ago.
What's Still Open
Two of the three withdrawal legs now lead into RAILGUN — independently, through different wallets, within hours of each other. That's not proof they're coordinated by the same operator (the Solana-side wallet is the common origin either way), but it's a consistent enough pattern to flag: whoever's moving this money treats RAILGUN as the default final step, the way other cases in this series default to Tornado Cash.
What's left unresolved: what happens to the ~$300K still sitting untouched at the DAI wallet, whether the NEAR-bound 256,000 DAI gets forwarded again once it's on a chain most tools don't watch, and whether the stuck Mayan Fast MCTP transfer ever gets claimed. That claim is the one piece of this whole flow that isn't finished yet — the money is real, it's sitting in a bridge contract with an attestation ready to be submitted, and nobody has submitted it. Worth checking back on all three.