The cross-chain stablecoin protocol Allbridge Core suffered a flash loan attack on its Solana liquidity pool, losing roughly $1.65 million (approximately 2.445 billion South Korean won), and the protocol has since suspended service. According to a Tokenpost report, analysis from security firms CertiK and PeckShield shows the attacker first borrowed a flash loan of about $1.12 million from Solana lending protocol Kamino, then repeatedly swapped within Allbridge’s USDC/USDT pool to artificially distort the ratio between the two stablecoins, ultimately extracting arbitrage profit before exiting. A flash loan is a mechanism that completes “borrow—act—repay” within a single transaction, allowing large sums to be moved without collateral — which is exactly why it keeps getting used as a weapon for DeFi price manipulation.
Editorial Take: How Much Does This Affect the USDT Card in Your Pocket
The bottom line first: if you use a custodial USDT card, this incident essentially has no impact on your deposits or spending. What got attacked was a liquidity pool belonging to a decentralized cross-chain bridge like Allbridge — not an issuer’s custodial wallet.
Two deposit paths need to be distinguished:
- Custodial deposits: You send USDT to a wallet address designated by the issuer, and the issuer handles custody, settlement, and currency conversion. Products like the MPCard Asia Elite variant, Bybit Card, and OKX Card all fall into this category. Your funds never pass through a third-party cross-chain bridge like Allbridge.
- Self-custody + cross-chain bridge deposits: You use a bridge to move assets from Chain A to Chain B first, then transfer into a card wallet. If you happened to route through Allbridge Core and your timing overlapped with this window, that’s where direct risk applies.
For the vast majority of users who simply want a USDT card to pay for ChatGPT, Claude, or cloud service subscriptions, there will be zero noticeable impact within 7 days; within 30 days, you might see cross-chain bridge protocols briefly tighten withdrawals or increase audit frequency; within 90 days, what’s actually worth watching is whether this kind of vulnerability pushes exchanges to tighten “source of funds” scrutiny. If you’re planning to open a new card, check the deposit path details in the MPCard review first, and avoid leaving large sums parked at any point along the chain.
Historical Comparison: Flash Loan Price Manipulation Is Not a New Script
The flash loan attack playbook repeats itself almost every year, following a highly consistent pattern — borrow a large sum → distort a pool’s quoted price → arbitrage at the distorted price → repay the principal within a single transaction.
- 2021 PancakeBunny: The attacker used a flash loan to manipulate the BUNNY/BNB pool’s price, extracting tens of millions of dollars — an early landmark case of this technique.
- 2022 Beanstalk: The attacker used a flash loan to borrow a massive sum within a single transaction to manipulate governance voting, directly draining the protocol’s treasury for a loss exceeding $180 million.
- This Allbridge incident: The scale was much smaller (about $1.65 million), but the attack surface expanded from “single-chain pool pricing” to “stablecoin ratio on both sides of a cross-chain bridge.”
The common thread: all exploited the vulnerability of pool-based pricing mechanisms that can be instantly manipulated in an uncollateralized, atomic transaction. The difference: this one targeted a cross-chain stablecoin bridge — a structure that handles both USDC and USDT simultaneously and must maintain ratio parity across chains, which is inherently more fragile than a single-chain, single-asset pool. It should be noted that the figures cited in this article — $1.65 million, the $1.12 million flash loan, etc. — are all drawn from the above Tokenpost report’s summary of CertiK and PeckShield’s analysis; refer to the formal post-incident reports from both security firms for on-chain details.
Compliance Perspective: Bridge Theft and Card Source-of-Funds Screening
From a compliance standpoint, the indirect impact of incidents like this deserves more attention than the direct impact. After a cross-chain bridge is drained, stolen funds are typically split, mixed, and moved across chains, eventually potentially flowing into exchanges or card issuance channels. This raises sensitivity around “source of funds” across the entire pipeline.
Users in the Asia-Pacific region should pay particular attention to differences in local attitudes toward crypto asset transfers. Japan’s regulatory stance on stablecoins and fund flows is relatively clear — see the Japan compliance guide; Hong Kong has been gradually tightening under its licensed-exchange framework — see the Hong Kong compliance guide. The current boundaries roughly are:
- Clearly permitted: Custodial deposits made through licensed exchanges or compliant issuers.
- Legal gray zone: Individuals using decentralized cross-chain bridges to transfer assets themselves — most jurisdictions have not explicitly banned this, but once funds become associated with a stolen address, subsequent exchange-side risk controls may trigger a freeze.
- Clearly high-risk: Receiving assets of unknown origin that have passed through a mixer.
Key Milestones Worth Watching Next
- Allbridge’s official post-mortem announcement — when the protocol resumes service, whether it will compensate affected users, and whether it will modify its pool pricing mechanism. Watch Allbridge’s official website and its official channels.
- Formal incident reports from CertiK / PeckShield — both firms will publish complete analyses with on-chain addresses, at which point the flow of the $1.65 million can be verified directly on Solscan.
- Movement of stolen funds — the 30 days following a flash loan attack are peak laundering period, which could trigger bulk risk-control actions against related addresses on the exchange side.
- Chain reactions among similar bridges — once one bridge is hit, cross-chain stablecoin bridges with similar architecture are usually found to have comparable vulnerabilities within weeks.
Editorial Recommendations
- Users holding custodial USDT cards like MPCard Asia Elite, Bybit Card, or OKX Card: no action needed. Your deposits don’t pass through Allbridge, so this incident doesn’t concern you.
- Users accustomed to transferring via cross-chain bridges before topping up: avoid routing through Allbridge Core in the short term, and check whether any recent address activity is connected to this incident. If you’re planning to top up for an AI subscription, going through an in-exchange deposit path directly is simpler — see the ChatGPT Plus scenario guide and Claude Code scenario guide.
- Users planning to apply for a new USDT card: prioritize custodial products with clear deposit paths — check the 2026 USDT Card Top 5 comparison of deposit methods first, and don’t leave large sums sitting in any DeFi pool or cross-chain bridge for extended periods.
A cross-chain bridge is always the segment of the stablecoin ecosystem with the largest attack surface — treating it as a “passageway” rather than a “parking lot” is the same reminder these kinds of news stories keep delivering.