星球日报
星球日报|8月 23, 2026 11:17
[SlowMist Reveals Details of Allbridge Cross-Chain Bridge Attack: Forged CCTP Messages + Flash Loans, Insufficient Minting Validation] Odaily Planet Daily News – The SlowMist security team disclosed that the cross-chain bridge project Allbridge was attacked on August 19, 2026, resulting in a loss of approximately $190,000. Notably, this attack was not executed instantly; the attacker began laying the groundwork nearly a month earlier by bypassing verification mechanisms through forged cross-chain messages. According to SlowMist's analysis, on July 26, the attacker directly called Circle's `MessageTransmitterV2.sendMessage` function on the Polygon chain, constructing a cross-chain message disguised in the style of CCTP, claiming a transfer of 1 million USDC. However, no actual USDC burn operation occurred. Subsequently, Circle followed the standard process and generated a valid attestation for the complete message. Approximately 24 days later, on August 19, the attacker waited for the Base Router to receive a legitimate CCTP deposit, increasing its balance to about 191,000 USDC. Just six seconds later, the attacker launched the attack. Using the previously forged message and attestation, the attacker called Allbridge's `receiveCctpMessage` function. Due to the project's lack of critical validation, the system mistakenly recognized the fake cross-chain message as a legitimate deposit and recorded a balance of 1 million USDC. The attacker then temporarily borrowed approximately 809,000 USDC through an Aave flash loan, matching the Router's balance with the forged amount. Leveraging internal credit records, the attacker invoked the transfer function and ultimately transferred out approximately 999,000 USDC (after deducting a 0.1% fee). After repaying the flash loan and associated fees, the attacker netted a profit of approximately $189,800. The root cause of this vulnerability lies in Allbridge's failure to verify the identities of the sender and receiver of the cross-chain message, as well as its failure to confirm whether USDC was genuinely minted and whether the balance had actually increased. Instead, the system directly trusted the amount and message hash data constructed by the attacker. SlowMist emphasized that on-chain message verification is not equivalent to the actual receipt of assets. Cross-chain protocols must not only verify the authenticity of messages but also ensure that the message source is trustworthy, the receiver is Circle's official `TokenMessengerV2`, and that asset minting and balance changes are confirmed before recording assets. This incident once again highlights the security risks in the message verification and asset settlement processes of cross-chain bridges.
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads