Allbridge Core — CCTP Base Chain Exploit (August 2026)
Summary
Allbridge Core, a cross-chain stablecoin bridge, suffered its third material security incident in 2026 on August 19 when an attacker exploited a missing balance verification in the protocol's newly deployed CCTP router on Base, draining 191,156 USDC. The attack, which involved crafting a forged Circle CCTP attestation message to book a phantom $1 million deposit before using a flash loan to cover the funding gap, represents a novel attack class with potential systemic implications for other protocols that accept CCTP attestations without verifying corresponding balance changes. This followed a $1.65 million flash loan exploit on Solana in July 2026 and an earlier BNB Chain exploit in April 2023.
Connected Entities
1 entitiesTimeline(6 events)
2023-04-02
Allbridge Core exploited on BNB Chain for approximately $570,000–$650,000 via flash loan pool price manipulation. Approximately $465,000 subsequently recovered through white-hat arrangement.
QuillAudits / Coinmonks2026-07-19
Allbridge Core exploited on Solana for approximately $1.65 million via same-asset swap input validation flaw, exploiting the same flash loan pool manipulation class as the 2023 attack on a deployment where the single-pool fix was not applied. Stolen funds bridged to Ethereum.
CoinDesk2026-07-19
Allbridge pauses cross-chain protocol approximately 30 minutes after the Solana exploit is detected. Team urges liquidity providers to withdraw and announces investigation.
The Block2026-07-20
Allbridge announces new version of Core will remove liquidity pools and shift routing to Circle CCTP and LayerZero to prevent pool imbalance attacks.
Decrypt2026-08-19
Allbridge Core's new CCTP router on Base exploited at 01:47 UTC. Attacker forges a Circle CCTP attestation message to book a phantom $1,000,000 deposit, flash-loans 808,844 USDC from Aave to cover the funding gap, and drains the router's entire 191,156 USDC reserve. Net attacker profit approximately 189,752 USDC. A copycat attacker reproduces the exploit within 25 minutes.
Defimon2026-08-19
Allbridge deregisters CCTP messengers on Arbitrum (05:15 UTC), Base (05:22 UTC), and Polygon (05:28 UTC) and revokes USDC allowances. Underlying contract logic not patched.
DefimonDecision Log
- #1publish⛓ pending8/22/2026, 12:06:17 PMhash: 81Ai2fMVWwkht8GuMbUwLRF6mjqeKLSncR6sd23gv1SU
18 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/22/2026, 12:06:09 PM
last updated: 8/22/2026, 3:23:22 PM
avoid.net — verified advice for a post-truth world