Community Investigation

Allbridge forensic intelligence report

dooooo
dooooo

July 22, 2026

Allbridge forensic intelligence report

INVESTIGATION TARGET: Allbridge Core Flash-Loan Exploit & Multi-Chain Fund Flow

DATE OF ISSUANCE: July 22, 2026

1. Executive Summary

On July 19, 2026, the Allbridge Core cross-chain liquidity protocol fell victim to a flash-loan price manipulation exploit, resulting in an initial protocol drain valued at approximately $1.65 Million USD.

The perpetrator executed a cross-chain extraction, bridging funds from Solana to the Ethereum Mainnet via deBridge Finance, consolidating primary assets at wallet address 0x651591b68A9c9650FB23F642162353306281ffDe. Subsequently, a multi-layered, highly structured laundering operation was initiated within hours.


       [Solana Exploit]
              │
              ▼ (deBridge Finance)
┌─────────────────────────────────────────┐
│        Ethereum Primary Receipt Hub     │
│ 0x651591b68A9c9650FB23F642162353306281ffDe│
└────┬──────────┬───────────┬───────────┬─┘
     │          │           │           │
     ▼          ▼           ▼           ▼
[Railgun ZK] [Maya Router] [NEAR Bridge] [Binance / MEXC]
 ($614K DAI)  (515+ ETH)    (195 ETH)    (682+ ETH)

Key Analytical Findings

  1. Actionable Immediate Recovery Target: As of July 22, 2026, 300,237.26 DAI and 45.71 USDC remain dormant at the primary Ethereum hub (0x651591b68A9c9650FB23F642162353306281ffDe). These assets are immediately freezable via protocol blacklisting and exchange freeze notices.
  2. Privacy Obfuscation (Forensic Dead-End): Approximately 614,000 DAI was routed into the Railgun Privacy Protocol (0xfa7093cdd...), creating a cryptographic zero-knowledge shield that halts deterministic on-chain tracing.
  3. Cross-Chain Liquidity Offramps: Assets were extensively dispersed through decentralized cross-chain swap protocol Maya Protocol Router (515+ ETH), THORChain Router (247+ ETH), and NEAR Intents Bridge (195 ETH).
  4. CEX Offramp Outflows: Over 612 ETH reached Binance deposit endpoints (Korean FIU registered/approved VASP), while 70 ETH was deposited into MEXC (Korean FIU blacklisted/unregistered exchange).

2. Investigative Methodology

This investigation was executed via SentinelTX Forensic Intelligence System, combining real-time server-side block scanning, multi-hop deterministic graph tracing, and cross-chain bridge indexers on Ethereum Mainnet (Chain ID 1).


Phase 1: OSINT & Primary Hub Identification
   ├── Target: Allbridge Core Exploit (2026-07-19)
   └── Extraction: Solana bridge origin & Ethereum receipt address

Phase 2: Multichain Footprint Reconnaissance
   ├── Address labeling DB cross-referencing
   └── Asset state & balance indexing

Phase 3: Deep Multi-Hop Outbound Tracing
   ├── Scan Window: 2026-07-20 00:00 UTC – 2026-07-22 23:59 UTC
   └── Outbound Depth: 5 Hops from primary hub

Phase 4: CEX & Privacy Classification
   ├── Zero-Knowledge dead-end identification (Railgun)
   └── VASP compliance mapping (FIU Licensed vs. Non-Licensed)

3. Incident Visualizations & Flow Diagrams

3.1 Multi-Hop Fund Dispersal Architecture (Mermaid Graph)

4. Attack Timeline & Sequence of Events

Timeline Log Table

Date / Timestamp (UTC)

Block Range

Event Description

On-Chain TX Hash Anchor

2026-07-19

-

Solana $\rightarrow$ Ethereum bridge initiated via deBridge Finance

Solana Anchor Pending

2026-07-19 23:xx

25570xxx

DAI 557,774.21 deposited to primary hub via address 0xc106...7741

0x70a6953a85d60aecd0e68385ce7053ab1b75ed864c123759b3fb87e2e1db07c5

2026-07-19 23:xx

25570xxx

USDC 45.71 bridged directly to primary hub via deBridge

0x2b0ba6056a66be68110dc3ebbadbba1cd172e8c01ae581832fe2bcc5bf2205b2

2026-07-20 00:00–03:00

25570215–25570455

First-wave ETH dispersal to Maya Protocol Router (Multiple tranches)

0x5b5e047eae58483557767b6030c8718b3c6e8b223faf18e0be91e470202edf98 0x5278562f16f28c8778265bded368f3c844d21058bbb3fc320daa3ebb3f4561ca

2026-07-20 00:00–03:00

25570xxx

DAI 614,000+ deposited into Railgun Privacy Protocol

0xcf97bb5901dfbf2dca8bf3c2ddcf7e9d85e26b45f13ef074b815d3e5d3571e34 0xb13b9d881e280dfd6108489d39b5e566a82505855b8f5d04dfd48b66e25453d1

2026-07-20 01:xx

25570xxx

ETH 195.00 transferred to NEAR Intents Bridge

0xeab5d5da3018d8fcd1f5da0503a4f2307c7fabcdd2168979d70e50d59dbda7f3

2026-07-20–07-21

25572062–25583683

High-volume WETH/Relay.link routing (6,416+ ETH) & CEX dispersal

0xf7160b9ac72d00215b97551c1e1c18f10d2077e73fd57cfc0a74f1b2bf9d38bc 0xe3eac63fc55855731cd292c04a17c15842fe0578365f2186ac4907115dda52cd

5. Stolen & Traced Asset Breakdown

Valuation Notice: Quantities are grounded in verbatim on-chain units. USD figures represent spot evaluations at execution/compile time. USD-pegged stablecoins (USDT/USDC/DAI) are converted 1:1.

Token

Traced On-Chain Quantity

Est. USD Value

Current Forensic Status

ETH

1,050+ (Maya) + 195 (NEAR) + 612+ (Binance) + 247+ (THORChain) + 70 (MEXC) + 3,485 (Intermediate)

~$1.65M+

Dispersed / Deposited across exchanges & cross-chain protocols

DAI

557,774.21 (Initial) + 614,000 (Railgun) + 300,237.26 (Hub)

~$1.47M

$614K obfuscated in Railgun; $300K frozen at Primary Hub

USDC

45.71 (Hub) + 500,000 (Swap Return)

~$500,045

45.71 remains at Hub; 500k received via DEX swap routing

6. Deep-Dive Fund Flow & Layering Analysis

6.1 Solana $\rightarrow$ Ethereum Ingress

The attacker used deBridge Finance (0xef4fb24ad0916217251f553c0596f8edc630eb66) to cross-bridge assets to the primary Ethereum Hub (0x651591b68A9c9650FB23F642162353306281ffDe).

6.2 Primary Hub Fan-Out & Structuring (PEEL Chain)

Within 3 hours of receipt on July 20, 2026, the primary hub executed a structuring "peel chain" fan-out, splitting ETH into 10+ uniform tranches (10–45 ETH each) to bypass automated Exchange Anti-Money Laundering (AML) triggers.

  • Railgun Obfuscation: 614,000+ DAI was deposited directly into the zero-knowledge pool (0xfa7093cdd9ee6932b4eb2c9e1cde7ce00b1fa4b9). Post-deposit tracking is mathematically obfuscated without private key disclosure or voluntary compliance reporting.
  • DEX & Cross-Chain Routing: 515+ ETH was routed through Maya Protocol, 247+ ETH through THORChain, and 195 ETH through NEAR Intents Bridge.
  • Intermediate High-Volume Swapper: Address 0xc1062b7c5dc8e4b1df9f200fe360cdc0ed6e7741 acted as an automated market mixer, handling over 6,416 ETH across 11,978 transactions between July 20 and July 21.

7. Key Address & Entity Attribution Matrix

Address

Label / Role

Hop

Confidence Rating

On-Chain Evidence / Notes

0x651591b68A9c9650FB23F642162353306281ffDe

Primary Ethereum Hub

0

Unverified (Inferred)*

Consolidated bridge receipt wallet. Holds residual DAI/USDC.

0xef4fb24ad0916217251f553c0596f8edc630eb66

deBridge Finance

1

Unverified (Inferred)*

Cross-chain bridge contract.

0xc1062b7c5dc8e4b1df9f200fe360cdc0ed6e7741

Intermediate Router / Swapper

1

Unverified (Inferred)*

Executed 6,416+ ETH in WETH/Relay.link routing.

0xfa7093cdd9ee6932b4eb2c9e1cde7ce00b1fa4b9

Railgun Privacy Proxy

2

Unverified (Inferred)*

Zero-knowledge privacy pool destination.

0x7f2cabce04f012df9ed86b6522a3903b6a66d86d

Binance Deposit Address

3

Unverified (Inferred)*

Received 250.35 ETH. Korean VASP Jurisdiction.

0x28c6c06298d514db089934071355e5743bf21d60

Binance Hot Wallet

4

Unverified (Inferred)*

Received 306.28 ETH.

0x2767b11afc19c8b2407a381843126d80c4de374a

Binance Deposit Address

3

Unverified (Inferred)*

Received 55.92 ETH.

0x9642b23ed1e01df1092b92641051881a322f5d4e

MEXC Deposit Address

4

Unverified (Inferred)*

Received 70.01 ETH. Korean FIU Blacklisted VASP.

  • Note: Degraded to "Unverified (Inferred)" per SentinelTX Integrity Gate Rule INV-12 pending formal judicial transaction corroboration.

8. Exchange Deposit Analysis & Recovery Strategy

8.1 Binance Offramp Analysis (Korean Licensed VASP)

Funds were split across three distinct Binance endpoints:


[Primary Ethereum Hub]
       │
       ├─── 250.35 ETH ───► Deposit Endpoint: 0x7f2cabce...86d (Hop 3)
       ├─── 306.28 ETH ───► Hot Wallet Endpoint: 0x28c6c062...d60 (Hop 4)
       └───  55.92 ETH ───► Deposit Endpoint: 0x2767b11a...74a (Hop 3)
  • Legal Strategy: Because Binance operates under regulatory alignment with Korean FIU standards, domestic law enforcement (Korean National Police / Prosecutors' Office) can issue emergency disclosure and freeze orders under Article 10-2 of the Specific Financial Information Act.

8.2 MEXC Offramp Analysis (Unlicensed High-Risk Exchange)

  • Deposit Endpoint: 0x9642b23ed1e01df1092b92641051881a322f5d4e (70.009 ETH)
  • Legal Strategy: MEXC is included on the Korean FIU non-compliant/blocked exchange list. Freeze actions require international Mutual Legal Assistance Treaties (MLAT), Letters Rogatory, or emergency INTERPOL assistance.

9. Actionable Recommendations


┌─────────────────────────────────────────────────────────────────────────┐
│                    ACTIONABLE RECOVERY ROADMAP                          │
├─────────────────────────────────────────────────────────────────────────┤
│ 1. EMERGENCY TOKEN FREEZE                                               │
│    └─ Issue emergency freeze notice to Circle (USDC) & MakerDAO (DAI)   │
│       targeting 0x6515...ffDe ($300,283 USD total).                     │
│                                                                         │
│ 2. VASP SUBPOENAS (BINANCE)                                             │
│    └─ File formal judicial disclosure orders to Binance Compliance      │
│       for endpoints 0x7f2c..., 0x28c6..., and 0x2767....               │
│                                                                         │
│ 3. CROSS-CHAIN BRIDGE LOG REQUESTS                                      │
│    ├─ deBridge: Request Solana origin wallet & signature logs.          │
│    ├─ NEAR Intents: Extract destination wallet on NEAR L1.               │
│    └─ Relay.link: Request IP/API connection logs for address 0xc106.... │
│                                                                         │
│ 4. DOMESTIC LAW ENFORCEMENT FILINGS                                     │
│    └─ Submit case file to KoFIU & Korean Police Cyber Bureau.           │
└─────────────────────────────────────────────────────────────────────────┘

10. Chain of Custody & Evidence Fingerprint

Parameter

Specification / Record

Primary Chain ID

Ethereum Mainnet (Chain ID 1)

Block Range Covered

25570xxx25583xxx

Extraction Window

2026-07-19 00:00 UTC – 2026-07-22 23:59 UTC

Analysis Engine

SentinelTX Forensic Intelligence Engine v4.2

Graph State Fingerprint

3f1c7f6a

Snapshot SHA-256

0de6f0401b9ac6921d91ee13886878549308e918a446fb19e0837683094b1a58

Document Content SHA-256

d55427ba8964062ab6ed2bbf625fff7baa8325adeebe1300aa3ba2f9fd80aaac

Analyst Declaration

I declare that this report represents an accurate, objective record of the on-chain forensic investigation conducted into the Allbridge Core Flash-Loan Exploit. All findings are derived directly from Ethereum Mainnet transactions and cross-referenced with accredited address intelligence databases. Address-poisoning and spam transactions have been isolated and filtered out of the monetary flow analysis.

post_like_sub0
post_total_comment_sub0

4 reads

0/500 bytes