Refreshed 1m ago· updates every 6h

Allbridge (2026) — Crypto Hack

Not Recovered
Aug 19, 2026·
BasePolygon
Amount Stolen
$190K
~191,156 USDC drained from the Base router
Recovered
$0

Attacker forged a Circle CCTP message on Polygon (no USDC burned), waited ~24 days, then used an Aave flash loan to drain ~$190K from Allbridge's Base router.

Summary

Attacker forged a Circle CCTP message on Polygon (no USDC burned), waited ~24 days, then used an Aave flash loan to drain ~$190K from Allbridge's Base router.

How It Was Compromised — Bridge via Forged CCTP Message / Flash Loan

BridgeForged CCTP Message / Flash Loan

On July 26, 2026, the attacker called Circle's MessageTransmitterV2.sendMessage on Polygon to construct a CCTP-style message claiming a 1,000,000 USDC transfer with no actual burn. Circle issued a valid attestation. On August 19, six seconds after a genuine CCTP deposit brought Allbridge's Base router balance to ~191,156 USDC, the attacker redeemed the forged message. Allbridge's CCTPTokenMessenger lacked sender/recipient validation and credited the fake amount, then the attacker used an 808,844 USDC Aave flash loan to top up the router balance, withdrew ~999,000 USDC, repaid the loan, and netted ~189,752 USDC. SlowMist's root-cause analysis: message attestation does not equal asset arrival; the protocol trusted attacker-constructed amounts without confirming actual minting or balance increases.

Fund Flow & Laundering Analysis

Profit of ~189,752 USDC remained in the attacker's control; no funds returned or bounty settled.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.