Loading...
The SlowMist security team revealed that the cross chain bridge project Allbridge was attacked on August 19, 2026, resulting in a loss of approximately $190000. The attacker bypassed verification by forging CCTP messages, constructed false messages claiming to transfer 1 million USDC on the Polygon chain, and launched attacks at the opportunity of the Base Router's real deposit balance of 191000 USDC. The attacker used forged messages to call Allbridge's receptiCctpMessage function, causing the system to mistakenly believe that there was a deposit of 1 million USDC. They then borrowed 809000 USDC through Aave Lightning Loan to match the balance, and ultimately transferred 990000 USDC. After deducting transaction fees, the net profit was approximately 189800 USD. Allbridge did not verify the identity of the cross chain message sender and the true casting of assets, resulting in the system directly trusting false data.