Huo Xing Finance reports that the SlowMist security team disclosed that the cross-chain bridge project Allbridge suffered an attack on August 19, 2026, resulting in losses of approximately $190,000. Notably, this attack was not executed immediately; the attacker began planning nearly a month in advance, bypassing verification mechanisms by forging cross-chain messages. According to SlowMist’s analysis, on July 26, the attacker directly called Circle’s MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a forged cross-chain message mimicking CCTP format, falsely claiming a transfer of 1 million USDC—while no actual USDC burn occurred. Subsequently, Circle generated a valid attestation for this complete message following its standard procedure. Approximately 24 days later, on August 19, the attacker waited until the Base Router received a legitimate CCTP deposit, increasing its balance to approximately 191,000 USDC, and launched the attack just six seconds later. The attacker then invoked Allbridge’s receiveCctpMessage function using the previously forged message and its valid attestation. Due to the project’s lack of critical validation checks, the system mistakenly treated the fraudulent cross-chain message as a legitimate deposit and recorded a fictitious 1 million USDC credit. The attacker then temporarily borrowed approximately 809,000 USDC via an Aave flash loan to match the router’s balance with the forged amount and invoked the transfer function using internal credit records, ultimately withdrawing approximately 999,000 USDC (after deducting a 0.1% fee). After repaying the flash loan and fees, the attacker netted approximately $189,800. The root cause of this vulnerability lies in Allbridge’s failure to verify the identity of the sender and recipient of the cross-chain message, as well as its failure to confirm whether USDC was genuinely minted or whether the balance had actually increased—instead, it blindly trusted the amount and message hash data provided by the attacker. SlowMist emphasized that on-chain message validation does not equate to actual asset receipt. Cross-chain protocols must not only verify message authenticity but also ensure that the message originates from a trusted source, that the recipient is Circle’s official TokenMessengerV2, and that asset minting and balance changes are confirmed before any accounting takes place. This incident once again highlights the security risks inherent in cross-chain bridges during message validation and asset settlement phases.
SlowMist Discloses Details of the Allbridge Cross-Chain Bridge Attack: Fake CCTP Messages, Flash Loans, and Inadequate Minting Verification
MarsBitShare
On-chain news: SlowMist disclosed the attack method used against the cross-chain bridge Allbridge on August 19, 2026, resulting in a $190,000 loss. On July 26, the attacker forged a CCTP-style message, tricking Circle into issuing a valid attestation. A legitimate deposit on the Base Router on August 19 enabled the attacker to exploit a verification gap in Allbridge’s receiveCctpMessage function. Using Aave flash loans, the attacker drained nearly 1 million USDC. SlowMist’s project announcement emphasizes the need for cross-chain protocols to verify both message authenticity and asset balances before recording transactions.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.
