ChainCatcher report: SlowMist Security Team disclosed that the cross-chain bridge project Allbridge was attacked on August 19, 2026, resulting in a loss of approximately $190,000. Notably, this attack was not executed immediately; the attacker began laying the groundwork nearly a month earlier by forging cross-chain messages to bypass validation mechanisms. According to SlowMist’s analysis, on July 26, the attacker directly called Circle’s MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a forged cross-chain message mimicking the CCTP format, falsely claiming a transfer of 1 million USDC—while no actual USDC burn occurred. Subsequently, Circle generated a valid attestation for this complete message following its standard process. Approximately 24 days later, on August 19, the attacker waited until the Base Router received a legitimate CCTP deposit, increasing its balance to approximately 191,000 USDC, and launched the attack just six seconds later. The attacker then used the previously forged message and its valid attestation to call Allbridge’s receiveCctpMessage function. Due to the project’s lack of critical validation checks, the system mistakenly treated the fraudulent cross-chain message as a genuine deposit and recorded a balance of 1 million USDC. The attacker then borrowed approximately 809,000 USDC via an Aave flash loan to match the router’s balance with the forged amount and invoked the transfer function using internal credit records, ultimately withdrawing approximately 999,000 USDC (after deducting a 0.1% fee). After repaying the flash loan and fees, the attacker netted approximately $189,800. The root cause of this vulnerability lies in Allbridge’s failure to verify the identity of the sender and recipient of the cross-chain message, as well as its failure to confirm whether USDC was genuinely minted or whether the balance had actually increased—instead, it blindly trusted the amount and message hash data provided by the attacker. SlowMist emphasized that on-chain message validation does not equate to actual asset receipt. Cross-chain protocols must not only verify message authenticity but also ensure that the message originates from a trusted source, that the recipient is Circle’s official TokenMessengerV2, and that asset minting and balance changes are confirmed before recording any assets. This incident once again highlights the security risks inherent in cross-chain bridges during message validation and asset settlement phases.
Slow Mist Reveals Allbridge Cross-Chain Bridge Attack Details: Fake CCTP Messages, Flash Loans, and Insufficient Minting Verification
ChaincatcherShare
On-chain news from ChainCatcher reveals a security breach in the cross-chain bridge Allbridge, resulting in a $190,000 loss on August 19, 2026. The attacker forged CCTP messages on July 26 by simulating a 1 million USDC transfer on Polygon. A valid attestation was generated, and 24 days later, the attacker exploited the receiveCctpMessage function. Due to insufficient verification, the system credited 1 million USDC. Using Aave flash loans, the attacker drained 999,000 USDC. Slow Mist emphasized the need for cross-chain protocols to verify sender identity, message origin, and actual asset minting.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.
