Across Protocol, Allbridge, and TeleSwap collectively lost more than $5.7 million to separate exploits over the past week, adding three fresh entries to what is already a bruising year for blockchain bridge security.
How each attack played out
Across Protocol was the hardest hit. On Friday, the protocol disclosed an attack on its Solana deployment and immediately paused deposits on the affected chain. On-chain analysis of two flagged EVM addresses showed $3.35 million flowing in during the early hours of the exploit. Most of that money has since moved to a single address now holding 1,500 ETH, worth roughly $2.85 million. Across said no user funds were at risk, the losses falling entirely on a relayer operated by Risk Labs, the foundation behind the protocol. A full post-mortem is promised for next week. The attacker pre-funded wallets through Tornado Cash on Ethereum and no-KYC exchange FixedFloat on Solana, both common tools in the illicit-actor playbook.
Sunday brought a flash loan attack on Allbridge, again on Solana. The exploit manipulated prices in one of Allbridge's liquidity pools and drained $1.66 million in USDC and USDT, which were then bridged across to Ethereum. In its initial alert, Allbridge made an unusual ask: anyone who had accidentally profited from the "temporary positive arbitrage window" the attack created was encouraged to return the funds voluntarily.
TeleSwap's incident is the oldest of the three. Pseudonymous on-chain investigator ZachXBT revealed on Monday that the self-described "Bitcoin DeFi hub" had been exploited back on July 15, with roughly $735,000 taken. ZachXBT publicly called out the team for failing to disclose the incident on its own.
The three attacks bring Protos's 2026 bridge-hack tally to 20 incidents and over $355 million in total losses for the year. Last week's $5.7 million looks modest against the bigger hits earlier in 2026, but the pace of incidents is not slowing.
This article is for informational purposes only and does not constitute financial advice.



