Allbridge (2026) — Crypto Hack
Not RecoveredAttacker forged a Circle CCTP message on Polygon (no USDC burned), waited ~24 days, then used an Aave flash loan to drain ~$190K from Allbridge's Base router.
Summary
Attacker forged a Circle CCTP message on Polygon (no USDC burned), waited ~24 days, then used an Aave flash loan to drain ~$190K from Allbridge's Base router.
How It Was Compromised — Bridge via Forged CCTP Message / Flash Loan
On July 26, 2026, the attacker called Circle's MessageTransmitterV2.sendMessage on Polygon to construct a CCTP-style message claiming a 1,000,000 USDC transfer with no actual burn. Circle issued a valid attestation. On August 19, six seconds after a genuine CCTP deposit brought Allbridge's Base router balance to ~191,156 USDC, the attacker redeemed the forged message. Allbridge's CCTPTokenMessenger lacked sender/recipient validation and credited the fake amount, then the attacker used an 808,844 USDC Aave flash loan to top up the router balance, withdrew ~999,000 USDC, repaid the loan, and netted ~189,752 USDC. SlowMist's root-cause analysis: message attestation does not equal asset arrival; the protocol trusted attacker-constructed amounts without confirming actual minting or balance increases.
Fund Flow & Laundering Analysis
Profit of ~189,752 USDC remained in the attacker's control; no funds returned or bounty settled.