On August 19, 2026, cross-chain bridge Allbridge was drained of roughly $190,000 in USDC on Base after an attacker fed its router a forged Circle CCTP (Cross-Chain Transfer Protocol) message and used a flash loan to make the fake claim payable. The theft was the second exploit to hit Allbridge in 2026, following the Allbridge Core flash-loan attack in July.
What happened
The attack was staged nearly a month in advance. On July 26, 2026, the attacker called Circle's MessageTransmitterV2.sendMessage on Polygon and crafted a message mimicking the CCTP format — falsely claiming a 1,000,000 USDC transfer — even though no actual USDC burn ever occurred. Circle's standard process still generated a valid attestation for the well-formed message. The root cause was on Allbridge's side: its receiveCctpMessage function did not verify the message's sender and recipient, nor independently confirm that a genuine mint or balance increase had taken place; it trusted the attestation as proof of funds. On August 19 the attacker waited for a legitimate CCTP deposit to raise the Base router's balance to about 191,156 USDC, then — just six seconds later — submitted the pre-forged 1,000,000 USDC claim and topped the router up with an 808,844 USDC flash loan from Aave. With the balance now large enough to satisfy the fraudulent claim, they withdrew roughly 999,000 USDC, paid the 0.1% protocol fee, repaid the flash loan, and netted about $189,751.
Aftermath
The drained funds were the legitimate ~191,156 USDC that had just entered the router; the flash loan was repaid within the same transaction. SlowMist and the DeFiHackLabs community published post-mortems reconstructing the month-long attack, but as of late September 2026 there was no public statement from the Allbridge team laying out remediation steps or reimbursement, and no recovery had been reported, so the status here is stolen.
Why it matters
Circle's CCTP attestation certifies that a message is well-formed, not that value was actually burned on the source chain — a distinction integrators must enforce themselves. Allbridge treated a valid attestation as a guarantee of funds, letting a message that any account could construct stand in for a real cross-chain transfer. As with earlier bridge failures such as Wormhole, the lesson is that verifying a signature or attestation is not the same as verifying that the underlying assets exist. That a protocol could be hit twice in one year — first by flash-loan pool manipulation, then by a forged-message mint — highlights how many independent trust assumptions a cross-chain bridge must get right.
Sources & on-chain evidence
- [01]slowmist.medium.comhttps://slowmist.medium.com/a-cross-chain-attack-spanning-one-month-analysis-of-the-allbridge-hack-32a6183bce08
- [02]kucoin.comhttps://www.kucoin.com/news/flash/slow-mist-reveals-allbridge-cross-chain-bridge-attack-details-fake-cctp-messages-flash-loans-and-insufficient-minting-verification
- [03]github.comhttps://github.com/SunWeb3Sec/DeFiHackLabs/pull/1275
- [04]shattered.iohttps://shattered.io/allbridge-hack-cctp-forged-message-2026/