SlowMist details Allbridge exploit involving forged CCTP-style message and flash loan

SlowMist details Allbridge exploit involving forged CCTP-style message and flash loan

N
News Editor
2026-08-23 11:16:24
SlowMist said cross-chain bridge project Allbridge was exploited on Aug. 19, 2026, with losses of about $190,000. The security firm said the attack was prepared weeks in advance rather than executed in a single move. According to its analysis, the attacker first called Circle’s MessageTransmitterV2.sendMessage on Polygon on July 26 to craft a message that looked like a CCTP transfer for 1 million USDC, even though no USDC burn ever took place. Circle then issued a valid attestation for that complete message under its normal process. Roughly 24 days later, after the Base Router received a real CCTP deposit and its balance rose to about 191,000 USDC, the attacker moved within six seconds. Using the forged message and attestation, the attacker called Allbridge’s receiveCctpMessage function. SlowMist said missing checks caused the protocol to treat the fake cross-chain message as a real deposit and book a 1 million USDC credit. The attacker then borrowed about 809,000 USDC through an Aave flash loan, matched the Router balance to the forged amount, and used the internal credit record to transfer out about 999,000 USDC after a 0.1% fee. After repaying the flash loan and fees, net profit was about $189,800.

SlowMist said cross-chain bridge project Allbridge was attacked on Aug. 19, 2026, with losses of about $190,000. The security team said the exploit was not carried out instantly. Instead, the attacker began setting up nearly a month earlier and used a forged cross-chain message to get past the protocol’s checks.

The setup began on July 26 on Polygon

According to SlowMist’s analysis, the attacker directly called Circle’s MessageTransmitterV2.sendMessage function on Polygon on July 26 and built a message made to resemble a CCTP-style cross-chain transfer. The message claimed a transfer of 1 million USDC, but no USDC burn actually occurred.

Circle then generated a valid attestation for that complete message through its standard process.

The exploit was triggered six seconds after a real deposit arrived

About 24 days later, on Aug. 19, the attacker waited until the Base Router received a real CCTP deposit and its balance increased to about 191,000 USDC. Just six seconds later, the attack was launched.

The attacker used the previously forged message and attestation to call Allbridge’s receiveCctpMessage function. SlowMist said the project lacked critical checks, so the system treated the fake cross-chain message as a real deposit and recorded a 1 million USDC credit.

Aave flash loan used to align the balance

The attacker then temporarily borrowed about 809,000 USDC through an Aave flash loan, bringing the Router balance in line with the forged amount. Using the internal credit record, the attacker called the transfer function and moved out about 999,000 USDC after a 0.1% fee.

After repaying the flash loan and related fees, the attacker’s net profit came to about $189,800.

SlowMist says the failure was in message and asset settlement checks

SlowMist said the root cause was that Allbridge did not verify the identities of the cross-chain message sender and recipient, and did not confirm whether USDC had actually been minted or whether the balance had truly increased. Instead, the protocol directly trusted the amount and message hash data constructed by the attacker.

The firm said on-chain message verification is not the same as confirming that real assets have arrived. For cross-chain protocols, checking message authenticity alone is not enough. They also need to verify that the message source is trusted, that the recipient is Circle’s official TokenMessengerV2, and that asset booking happens only after actual minting and balance changes are confirmed.

The incident, SlowMist said, again exposed security risks in cross-chain bridges at the message verification and asset settlement stages.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
20

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.