Allbridge cross-chain bridge exploited for $190,000 via forged CCTP-style message and missing validation checks.
Security & Exploits ·
Allbridge's cross-chain bridge suffered an exploit resulting in approximately $190,000 in losses, though the attack unfolded over nearly a month, according to security analysis. On July 26, an attacker crafted a forged message mimicking Circle's CCTP standard by calling Circle's MessageTransmitterV2 directly on Polygon, falsely claiming a 1,000,000 USDC transfer without burning any actual tokens. Circle then generated a valid attestation for the complete fabricated message. The attacker waited approximately 24 days; on August 19, just six seconds after a genuine CCTP deposit brought roughly 191,000 USDC to Allbridge's Base Router, the attacker submitted the forged message to Allbridge's receiveCctpMessage function.
Allbridge's validation gaps allowed the forged message to be accepted as legitimate. The contract credited 1,000,000 USDC internally without confirming actual token minting. An Aave flash loan then supplied an additional 808,844 USDC to the Router, temporarily aligning its balance with the falsely credited amount. The Router's receiveToken function, relying solely on internal accounting records, transferred approximately 999,000 USDC to the attacker after deducting a 0.1% fee, yielding a net profit near $189,751.
The core vulnerability lay in missing verification of the message sender (which should have been Circle's TokenMessenger) and recipient address. Allbridge trusted the attacker-supplied amount and message hash without independently confirming actual USDC minting or corresponding balance changes. Most drained funds originated from legitimate cross-chain deposits that had recently arrived but remained undelivered to end users.