BTC $78,903.19 +1.43%
ETH $2,480.05 +0.69%
BNB $703.56 +0.25%
XRP $1.48 -2.93%
SOL $98.30 +2.98%
TRX $0.3446 +0.20%
DOGE $0.0897 -3.93%
ADA $0.2206 -2.59%
BCH $270.67 -1.30%
LINK $11.61 +0.72%
HYPE $78.53 -4.46%
AAVE $132.41 -6.40%
SUI $0.7967 -6.44%
XLM $0.1932 -3.23%
ZEC $826.98 -2.84%
BTC $78,903.19 +1.43%
ETH $2,480.05 +0.69%
BNB $703.56 +0.25%
XRP $1.48 -2.93%
SOL $98.30 +2.98%
TRX $0.3446 +0.20%
DOGE $0.0897 -3.93%
ADA $0.2206 -2.59%
BCH $270.67 -1.30%
LINK $11.61 +0.72%
HYPE $78.53 -4.46%
AAVE $132.41 -6.40%
SUI $0.7967 -6.44%
XLM $0.1932 -3.23%
ZEC $826.98 -2.84%

cross-chain

All
Article
Flash

Slow Mist Reveals Details of the Allbridge Cross-Chain Bridge Attack: Forged CCTP Messages, Flash Loans, Insufficient Minting Result Verification

The Slow Mist security team disclosed that the cross-chain bridge project Allbridge was attacked on August 19, 2026, resulting in a loss of approximately $190,000. Notably, this attack was not executed instantly; the attacker had begun laying the groundwork nearly a month prior and bypassed the verification mechanism by forging cross-chain messages. According to Slow Mist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as a CCTP style message, claiming that a transfer of 1 million USDC existed, but in reality, no USDC destruction operation took place. Subsequently, Circle generated a valid verification proof (attestation) for this complete message according to normal procedures.About 24 days later, on August 19, the attacker waited for the Base Router to receive a real CCTP deposit, increasing the balance to approximately 191,000 USDC, and initiated the attack just 6 seconds later. The attacker utilized the previously forged message and verification proof to call Allbridge's receiveCctpMessage function. Due to the project's lack of critical verification, the system mistakenly recognized the false cross-chain message as a real deposit and recorded a limit of 1 million USDC. The attacker then temporarily borrowed approximately 809,000 USDC through an Aave flash loan, matching the Router balance with the forged amount, and used the internal credit record to call the transfer function, ultimately transferring out approximately 999,000 USDC (after a 0.1% fee). After repaying the flash loan and fees, the attacker netted a profit of about $189,800. The root cause of this vulnerability lies in Allbridge's failure to verify the identities of the sender and receiver of the cross-chain message, as well as not confirming whether USDC was genuinely minted and whether the balance actually increased, instead directly trusting the amounts and message hash data constructed by the attacker. Slow Mist emphasizes that on-chain message verification does not equate to the actual arrival of real assets. Cross-chain protocols not only need to verify the authenticity of messages but must also ensure that the message source is trustworthy, that the receiver is Circle's official TokenMessengerV2, and that asset accounting can only proceed after confirming the actual minting of assets and changes in balance. This incident once again highlights the security risks of cross-chain bridges in the message verification and asset settlement processes.

Gate Research Institute: Robinhood Chain presents a dual-layer structure of Meme+RWA, Gate DEX opens up multi-chain access to the ecosystem

Gate Research Institute released a thematic report on Robinhood Chain. The report points out that Robinhood Chain aims for tokenized stocks, ETFs, and other RWAs as its long-term direction, but in the early stages of the mainnet launch, growth is primarily driven by Meme, Launchpad, and Uniswap trading, forming a structure where RWA serves as a long-term asset endpoint and Meme acts as a short-term liquidity engine. The high turnover of popular tokens such as CASHCAT and PONS reflects that the market is pricing around the Robinhood brand, on-chain retail trading culture, and launch platform traffic.The report also believes that Gate DEX's comprehensive access to Robinhood Chain supplements the ecosystem's external multi-chain entry points. In the early development stage of Robinhood Chain, AMMs like Uniswap mainly undertake price discovery and liquidity formation for on-chain assets, while Gate DEX complements the inflow paths for external funds and users through asset discovery, trading entry, and cross-chain capabilities. Gate Alpha supports the discovery and trading of ecosystem assets and multiple launch platforms, while Gate Wallet, Swap, professional trading, and market modules simultaneously cover this network; relying on Across and LayerZero, users can conduct cross-chain exchanges between BSC, Ethereum, Base, and Robinhood Chain. Overall, Gate DEX mainly undertakes asset distribution and fund routing functions within the ecosystem, helping Robinhood Chain connect with a broader multi-chain user base by lowering the operational threshold for users to discover assets, enter cross-chain, and participate in trading.

Allbridge suffered a loss of approximately $1.65 million due to a flash loan attack, and the cross-chain protocol has been suspended

According to Decrypt, the cross-chain bridge protocol Allbridge has suspended its Core protocol due to a flash loan attack, with the attacker having stolen approximately $1.65 million in assets from the Solana stablecoin liquidity pool.According to analysis by blockchain security firms PeckShield and CertiK, the attacker borrowed $1.12 million in flash loan funds through the Solana lending protocol Kamino, and then manipulated the price mechanism within the Allbridge pool through multiple stablecoin exchange operations to exchange assets at a low price, subsequently transferring the funds across chains to an Ethereum address.During the attack, the attacker exchanged several thousand dollars in USDT to obtain approximately $2.24 million in USDC, and then bridged the funds to Ethereum for further dispersal. It is currently unclear whether some of the funds can still be recovered.Allbridge stated that the team has suspended the Core protocol for security reasons and has requested affected liquidity providers to withdraw their funds immediately. Due to the attack causing an imbalance in the liquidity pool, some traders profited from arbitrage opportunities. Allbridge has called on relevant users to return their profits, stating that the funds will be used to compensate affected LPs.The team indicated that there is no further risk to user funds at this time and will release a detailed incident analysis report after completing the investigation, while also planning to relaunch the Core protocol after removing the liquidity pool. This is the second time Allbridge has encountered a similar flash loan attack. In April 2023, the protocol's BNB Chain liquidity pool suffered a loss of approximately $573,000 due to a similar vulnerability, after which the project team stated that they had recovered most of the funds and adjusted the liquidity calculation mechanism.
app_icon
ChainCatcher Building the Web3 world with innovations.