Skip to content
Est. MMXXVIVol. VI · № 343RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 322Bridge Exploit

Allbridge Forged CCTP Message Exploit

An attacker fed Allbridge's Base router a forged Circle CCTP message and padded it with an Aave flash loan to drain about $190,000 in USDC that a real deposit had just credited.

Date
Victim
Allbridge
Chain(s)
Status
Funds Stolen

On August 19, 2026, cross-chain bridge Allbridge was drained of roughly $190,000 in USDC on Base after an attacker fed its router a forged Circle CCTP (Cross-Chain Transfer Protocol) message and used a flash loan to make the fake claim payable. The theft was the second exploit to hit Allbridge in 2026, following the Allbridge Core flash-loan attack in July.

What happened

The attack was staged nearly a month in advance. On July 26, 2026, the attacker called Circle's MessageTransmitterV2.sendMessage on Polygon and crafted a message mimicking the CCTP format — falsely claiming a 1,000,000 USDC transfer — even though no actual USDC burn ever occurred. Circle's standard process still generated a valid attestation for the well-formed message. The root cause was on Allbridge's side: its receiveCctpMessage function did not verify the message's sender and recipient, nor independently confirm that a genuine mint or balance increase had taken place; it trusted the attestation as proof of funds. On August 19 the attacker waited for a legitimate CCTP deposit to raise the Base router's balance to about 191,156 USDC, then — just six seconds later — submitted the pre-forged 1,000,000 USDC claim and topped the router up with an 808,844 USDC flash loan from Aave. With the balance now large enough to satisfy the fraudulent claim, they withdrew roughly 999,000 USDC, paid the 0.1% protocol fee, repaid the flash loan, and netted about $189,751.

Aftermath

The drained funds were the legitimate ~191,156 USDC that had just entered the router; the flash loan was repaid within the same transaction. SlowMist and the DeFiHackLabs community published post-mortems reconstructing the month-long attack, but as of late September 2026 there was no public statement from the Allbridge team laying out remediation steps or reimbursement, and no recovery had been reported, so the status here is stolen.

Why it matters

Circle's CCTP attestation certifies that a message is well-formed, not that value was actually burned on the source chain — a distinction integrators must enforce themselves. Allbridge treated a valid attestation as a guarantee of funds, letting a message that any account could construct stand in for a real cross-chain transfer. As with earlier bridge failures such as Wormhole, the lesson is that verifying a signature or attestation is not the same as verifying that the underlying assets exist. That a protocol could be hit twice in one year — first by flash-loan pool manipulation, then by a forged-message mint — highlights how many independent trust assumptions a cross-chain bridge must get right.

Sources & on-chain evidence

  1. [01]slowmist.medium.comhttps://slowmist.medium.com/a-cross-chain-attack-spanning-one-month-analysis-of-the-allbridge-hack-32a6183bce08
  2. [02]kucoin.comhttps://www.kucoin.com/news/flash/slow-mist-reveals-allbridge-cross-chain-bridge-attack-details-fake-cctp-messages-flash-loans-and-insufficient-minting-verification
  3. [03]github.comhttps://github.com/SunWeb3Sec/DeFiHackLabs/pull/1275
  4. [04]shattered.iohttps://shattered.io/allbridge-hack-cctp-forged-message-2026/

Related filings