Skip to main content
AVOID.NET
← Allbridge Core — CCTP Base Chain Exploit (August 2026)reviewed 2026-09-07 · 34 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Allbridge Core — CCTP Base Chain Exploit (August 2026) against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

1 claim

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #24[disputed][awaiting moderator]in section: Pattern of Repeated Exploit Vectors
    “The protocol's three-incident track record within a 39-month window, with each exploit involving a different root cause, suggests systemic deficiencies in security review processes and cross-chain integration testing rather than any single point of failure.”
    reviewerThe protocol's three-incident track record occurred within a 39-month window.Calendar math from the page's own timeline dates (2023-04-02 to 2026-08-19) is approximately 40.6 months, i.e. a 40-month span, not 39. No source was cited for the '39-month' figure; it appears to be an internal miscalculation.
    Proposed correction (not yet applied)
    The protocol's three-incident track record within a 40-month window, with each exploit involving a different root cause, suggests systemic deficiencies in security review processes and cross-chain integration testing rather than any single point of failure.

unverifiable

2 claims

No source the reviewer could reach confirms or contradicts the claim.

  1. #18[unverifiable][awaiting moderator]in section: July 2026 Solana Flash Loan Exploit
    “Allbridge paused the protocol approximately 30 minutes after the exploit was detected and urged liquidity providers to withdraw.”
    reviewerAllbridge paused the protocol approximately 30 minutes after the exploit was detected.None of the page's own cited sources, nor several additional outlets checked directly, state a specific 30-minute figure. Some third-party aggregation suggested a ~25-minute figure, but that could not be traced to any single fetchable primary article, so this specific number is treated as unverifiable rather than disputed.
  2. #31[unverifiable][awaiting moderator]in the timeline
    “Allbridge pauses cross-chain protocol approximately 30 minutes after the Solana exploit is detected. Team urges liquidity providers to withdraw and announces investigation.”
    reviewerAllbridge pauses cross-chain protocol approximately 30 minutes after the Solana exploit is detected.Same unverifiable '30 minutes' figure as flagged in sections[3]; grouped under the same defect_group.

partially supported

3 claims

The cited evidence supports part of the claim but not all of it.

  1. #11[partially supported][awaiting moderator]in section: Attack Replication and Systemic Risk
    “The broader implication is that Circle's sendMessage function can be used to obtain a valid attestation for an arbitrary payload that does not correspond to a real burn-and-mint event, and that protocols must not rely solely on attestation validity as a proxy for token settlement.”
    reviewerCircle's sendMessage function can be used to obtain a valid attestation for an arbitrary payload with no real burn-and-mint event, so protocols must not rely solely on attestation validity as a proxy for token settlement -- illustrated by the Asymmetric Research citation on the CCTP/Noble mint bug.The general point about the Allbridge exploit itself is well supported by Defimon, but the Asymmetric Research citation is being used to generalize the risk class; that source documents a related but mechanically different CCTP flaw (sender validation, not settlement validation), so the citation somewhat overstates its relevance to this specific claim.
  2. #26[partially supported][awaiting moderator]in section: Protocol Background
    “Allbridge integrates CCTP as an official integration partner of Circle, enabling zero-slippage USDC transfers on supported routes.”
    reviewerAllbridge integrates CCTP as an official integration partner of Circle, enabling zero-slippage USDC transfers on supported routes.The underlying fact -- that Allbridge has a genuine, longstanding CCTP integration -- is well supported. The specific phrase 'official integration partner of Circle' could not be found in Circle's or Allbridge's own materials and appears to be an inferential characterization rather than a documented designation.
  3. #32[partially supported][awaiting moderator]in the timeline
    “Allbridge announces new version of Core will remove liquidity pools and shift routing to Circle CCTP and LayerZero to prevent pool imbalance attacks.”
    reviewerAllbridge announces new version of Core will remove liquidity pools and shift routing to Circle CCTP and LayerZero to prevent pool imbalance attacks.The underlying fact (shift to CCTP/LayerZero routing) is true and well documented elsewhere, but the specific source cited on the page (Decrypt) does not itself support the CCTP/LayerZero detail -- only the more general 'no liquidity pools' point. A source that does directly substantiate the claim was located and fetched.

confirmed

28 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    “Allbridge Core, a cross-chain stablecoin bridge, suffered its third material security incident in 2026 on August 19 when an attacker exploited a missing balance verification in the protocol's newly deployed CCTP router on Base, draining 191,156 USDC.”
    reviewerOn August 19, an attacker exploited a missing balance verification in Allbridge's newly deployed CCTP router on Base, draining 191,156 USDC.Amount and date independently corroborated by Defimon and a SlowMist analysis syndicated on KuCoin.
  2. #2[confirmed][no action needed]in the summary
    “The attack, which involved crafting a forged Circle CCTP attestation message to book a phantom $1 million deposit before using a flash loan to cover the funding gap, represents a novel attack class with potential systemic implications for other protocols that accept CCTP attestations without verifying corresponding balance changes.”
    reviewerThe attacker crafted a forged Circle CCTP attestation message to book a phantom $1 million deposit and used a flash loan to cover the funding gap, representing a novel systemic risk for protocols accepting CCTP attestations without verifying balance changes.Mechanism and systemic framing match the primary technical write-up.
  3. #3[confirmed][no action needed]in the summary
    “This followed a $1.65 million flash loan exploit on Solana in July 2026 and an earlier BNB Chain exploit in April 2023.”
    reviewerThe August 2026 exploit followed a $1.65 million flash loan exploit on Solana in July 2026 and an earlier BNB Chain exploit in April 2023.Both prior incidents independently confirmed.
  4. #4[confirmed][no action needed]in section: August 2026 CCTP Base Chain Exploit
    “On August 19, 2026 at approximately 01:47 UTC, an attacker identified by address 0x2419432344b0b892e592b2601b98eae702ba360e exploited Allbridge Core's newly deployed CCTP router on Base, draining the router's entire reserve of 191,156 USDC.”
    reviewerOn August 19, 2026 at approximately 01:47 UTC, address 0x2419432344b0b892e592b2601b98eae702ba360e exploited the CCTP router on Base, draining its entire 191,156 USDC reserve.Address, timestamp (01:47:17 UTC), and amount match the source precisely.
  5. #5[confirmed][no action needed]in section: August 2026 CCTP Base Chain Exploit
    “According to analysis by Defimon, the vulnerability resided in the protocol's CCTPTokenMessenger.receiveCctpMessage function, which accepted Circle's attestation as proof of value transfer without verifying that USDC had actually been minted.”
    reviewerThe vulnerability was in receiveCctpMessage, which accepted Circle's attestation as proof of value transfer without verifying USDC had actually been minted.The general mechanism is confirmed by the primary source; the literal Solidity snippet require(receivedAmount > 0) quoted later in the same section could not be independently verified against deployed bytecode/source, though it is consistent with the described flaw.
  6. #6[confirmed][no action needed]in section: August 2026 CCTP Base Chain Exploit
    “The attacker crafted a fake CCTP deposit message on Polygon (reportedly prepared as early as July 25, 2026) claiming 1,000,000 USDC using Circle's generic sendMessage function, which attests arbitrary payloads with no burn-and-mint operation attached.”
    reviewerThe attacker's fake CCTP deposit message was crafted on Polygon and reportedly prepared as early as July 25, 2026, claiming 1,000,000 USDC via Circle's generic sendMessage function.Page's hedged phrasing ('reportedly prepared as early as July 25') accommodates the minor one-day variance between the two secondary reports.
  7. #7[confirmed][no action needed]in section: August 2026 CCTP Base Chain Exploit
    “To cover the gap between the phantom $1 million deposit and the router's actual 191,156 USDC balance, the attacker obtained an 808,844 USDC flash loan from Aave, redeemed 999,000 USDC from the router (less a 10 basis point fee), repaid the loan plus a 404 USDC premium, and netted approximately 189,752 USDC in profit.”
    reviewerThe attacker obtained an 808,844 USDC flash loan from Aave, redeemed 999,000 USDC (a 10bps fee), repaid the loan plus a 404 USDC premium, and netted approximately 189,752 USDC.Figures cross-checked arithmetically: 1,000,000 - 999,000 = 1,000 (10bps of $1M), matching the router fee Defimon reports.
  8. #8[confirmed][no action needed]in section: August 2026 CCTP Base Chain Exploit
    “A legitimate CCTP transfer had deposited 191,112 USDC into the router at block 50157342 at 01:47:11 UTC; the exploit executed three blocks later, claiming those funds before the bridge's own relayer could forward them to their intended recipient.”
    reviewerA legitimate CCTP transfer deposited 191,112 USDC at block 50157342 at 01:47:11 UTC, and the exploit executed three blocks later.Block delta matches exactly.
  9. #9[confirmed][no action needed]in section: Attack Replication and Systemic Risk
    “According to Defimon's analysis, a copycat attacker reproduced the exploit within 25 minutes of the original attack using ordinary retail tools, demonstrating that the vulnerability was not sophisticated and required no specialized access.”
    reviewerA copycat attacker reproduced the exploit within 25 minutes of the original attack using ordinary retail tools.Matches primary source precisely.
  10. #10[confirmed][no action needed]in section: Attack Replication and Systemic Risk
    “Defimon's report notes that Allbridge's immediate containment response — deregistering CCTP messengers on Arbitrum, Base, and Polygon — stopped further losses but did not patch the underlying contract logic, meaning any redeployment with a registered messenger would reopen the vulnerability unless the receiveCctpMessage function is rewritten to verify balance changes.”
    reviewerAllbridge's containment response (deregistering CCTP messengers on Arbitrum, Base, and Polygon) stopped further losses but did not patch the underlying contract logic.Directly supported by the cited source.
  11. #12[confirmed][no action needed]in section: Protocol Response
    “Following detection of the August 19 exploit, Allbridge deregistered CCTP messengers on Arbitrum at 05:15:52 UTC, Base at 05:22:51 UTC, and Polygon at 05:28 UTC.”
    reviewerAllbridge deregistered CCTP messengers on Arbitrum at 05:15:52 UTC, Base at 05:22:51 UTC, and Polygon at 05:28 UTC, and revoked USDC allowances.Times are internally consistent with the primary source's stated range.
  12. #13[confirmed][no action needed]in section: Protocol Response
    “According to Defimon's reporting, Allbridge did not modify the vulnerable contract logic and the underlying vulnerability remained unfixed as of the time of reporting.”
    reviewerAllbridge did not modify the vulnerable contract logic and the underlying vulnerability remained unfixed as of the time of reporting.This is time-bound to the reporting date; a later patch cannot be ruled out but no evidence of one was found.
  13. #14[confirmed][no action needed]in section: July 2026 Solana Flash Loan Exploit
    “On July 19, 2026 at approximately 17:51 UTC, Allbridge Core suffered a $1.65 million exploit on its Solana deployment.”
    reviewerOn July 19, 2026 at approximately 17:51 UTC, Allbridge Core suffered a $1.65 million exploit on its Solana deployment.Widely corroborated across five independent outlets cited on the page, plus additional outlets found in search.
  14. #15[confirmed][no action needed]in section: July 2026 Solana Flash Loan Exploit
    “The attacker borrowed $1.12 million USDC from the Solana lending protocol Kamino without collateral, then executed a series of same-asset swaps within Allbridge Core's USDC/USDT stablecoin pool — passing the same Pool account in both the send and receive roles of the swap instruction.”
    reviewerThe attacker borrowed $1.12 million USDC from Kamino without collateral, then executed same-asset swaps passing the same Pool account in both send and receive roles, causing internal accounting to be silently overwritten.Technical mechanism independently confirmed by BlockSec's on-chain analysis, which was not even one of the page's cited sources for this section but corroborates it.
  15. #16[confirmed][no action needed]in section: July 2026 Solana Flash Loan Exploit
    “Five self-swaps distorted the pool's recorded state sufficiently for the attacker to convert a small USDT input into approximately $2.24 million USDC before bridging funds from Solana to Ethereum.”
    reviewerFive self-swaps distorted the pool's recorded state, allowing the attacker to convert a small USDT input into approximately $2.24 million USDC.Matches BlockSec's independent on-chain reconstruction of the transaction.
  16. #17[confirmed][no action needed]in section: July 2026 Solana Flash Loan Exploit
    “The stolen funds were subsequently moved into privacy pools.”
    reviewerThe stolen funds were subsequently moved into privacy pools.Confirmed via secondary reporting, though the page's own directly cited sources (Decrypt, Cointelegraph, The Block) do not use the specific term 'privacy pools' in the portions retrievable.
  17. #19[confirmed][no action needed]in section: April 2023 BNB Chain Flash Loan Exploit
    “On April 1–2, 2023, Allbridge Core suffered an earlier flash loan exploit on BNB Chain in which attackers drained approximately $570,000 to $650,000 from USDT and BUSD liquidity pools.”
    reviewerOn April 1-2, 2023, Allbridge Core suffered a flash loan exploit on BNB Chain draining approximately $570,000-$650,000 from USDT and BUSD liquidity pools via a withdraw-function logic flaw allowing simultaneous liquidity-provider/swapper manipulation.Date and amount range confirmed by multiple sources; different outlets round the total loss differently ($570K-$650K), which the page's hedged range accommodates.
  18. #20[confirmed][no action needed]in section: April 2023 BNB Chain Flash Loan Exploit
    “The attacker drained approximately $289,900 in BUSD and $290,900 in USDT.”
    reviewerThe attacker drained approximately $289,900 in BUSD and $290,900 in USDT.Figures match the page's cited QuillAudits source; a secondary report cites marginally different cent-level figures for the same event.
  19. #21[confirmed][no action needed]in section: April 2023 BNB Chain Flash Loan Exploit
    “Following that incident, Allbridge worked with a white-hat researcher to recover approximately $465,000 and committed to deploying a single liquidity pool per chain — an architectural change intended to prevent same-transaction flash loan manipulation.”
    reviewerFollowing the 2023 incident, Allbridge worked with a white-hat researcher to recover approximately $465,000 and committed to deploying a single liquidity pool per chain.Both the recovery amount and the architectural commitment are independently corroborated.
  20. #22[confirmed][no action needed]in section: April 2023 BNB Chain Flash Loan Exploit
    “The July 2026 Solana exploit demonstrated that this architectural fix was not applied to Solana deployments, which retained the dual-pool structure needed for the same style of manipulation.”
    reviewerThe July 2026 Solana exploit demonstrated that the single-pool architectural fix was not applied to Solana deployments, which retained the dual-pool structure.TechTimes returned HTTP 403 on direct fetch; corroborated instead via search-engine synthesis of the same article plus consistent reporting elsewhere.
  21. #23[confirmed][no action needed]in section: Pattern of Repeated Exploit Vectors
    “Allbridge Core has suffered three distinct material security incidents across 2023 and 2026, each exploiting a different layer of the protocol's architecture.”
    reviewerAllbridge Core has suffered three distinct material security incidents (2023 BNB Chain, July 2026 Solana, August 2026 Base), each exploiting a different layer of the architecture.Supported by the cumulative record established in the other sections of this same page, each independently verified above.
  22. #25[confirmed][no action needed]in section: Protocol Background
    “Allbridge Core is a cross-chain stablecoin bridge that facilitates the transfer of USDC, USDT, and other stablecoins across multiple blockchains including Ethereum, Solana, Base, Arbitrum, Polygon, and BNB Chain, among others. The protocol supports both pool-based transfers and routing through Circle's Cross-Chain Transfer Protocol (CCTP).”
    reviewerAllbridge Core facilitates transfer of stablecoins across Ethereum, Solana, Base, Arbitrum, Polygon, and BNB Chain, supporting both pool-based transfers and CCTP routing.Confirmed directly against the official documentation.
  23. #27[confirmed][no action needed]in section: Protocol Background
    “L2BEAT classifies Allbridge as a bridge with on-chain contract activity verified across multiple chains.”
    reviewerL2BEAT classifies Allbridge as a bridge with on-chain contract activity verified across multiple chains.Confirmed with moderate confidence; the L2BEAT page could not be fully rendered by the fetch tool (client-side rendered SPA), so this relies on search-indexed content rather than a full direct render.
  24. #28[confirmed][no action needed]in section: Protocol Background
    “As of the time of the August 2026 exploit, the protocol had CCTP Bridge contracts deployed on Base (0x1efe2c85989d97febbd0743cdd79b9f0826314f6), Ethereum, and Arbitrum, among others.”
    reviewerAs of the August 2026 exploit, Allbridge had a CCTP Bridge contract deployed on Base at 0x1efe2c85989d97febbd0743cdd79b9f0826314f6.Directly confirmed on-chain via block explorer label.
  25. #29[confirmed][no action needed]in the timeline
    “Allbridge Core exploited on BNB Chain for approximately $570,000–$650,000 via flash loan pool price manipulation. Approximately $465,000 subsequently recovered through white-hat arrangement.”
    reviewerAllbridge Core exploited on BNB Chain for approximately $570,000-$650,000 via flash loan pool price manipulation; approximately $465,000 subsequently recovered through white-hat arrangement.Same underlying facts as the section 4 (April 2023) findings above, independently confirmed.
  26. #30[confirmed][no action needed]in the timeline
    “Allbridge Core exploited on Solana for approximately $1.65 million via same-asset swap input validation flaw, exploiting the same flash loan pool manipulation class as the 2023 attack on a deployment where the single-pool fix was not applied. Stolen funds bridged to Ethereum.”
    reviewerAllbridge Core exploited on Solana for approximately $1.65 million via same-asset swap input validation flaw; stolen funds bridged to Ethereum.Consistent with section 4 findings above.
  27. #33[confirmed][no action needed]in the timeline
    “Allbridge Core's new CCTP router on Base exploited at 01:47 UTC. Attacker forges a Circle CCTP attestation message to book a phantom $1,000,000 deposit, flash-loans 808,844 USDC from Aave to cover the funding gap, and drains the router's entire 191,156 USDC reserve. Net attacker profit approximately 189,752 USDC. A copycat attacker reproduces the exploit within 25 minutes.”
    reviewerAllbridge Core's new CCTP router on Base was exploited at 01:47 UTC on August 19, 2026, via a forged CCTP attestation and flash loan, draining 191,156 USDC for a ~189,752 USDC profit; a copycat reproduced the exploit within 25 minutes.Duplicate of confirmed claims already verified in sections[0]-[1]; consistent.
  28. #34[confirmed][no action needed]in the timeline
    “Allbridge deregisters CCTP messengers on Arbitrum (05:15 UTC), Base (05:22 UTC), and Polygon (05:28 UTC) and revokes USDC allowances. Underlying contract logic not patched.”
    reviewerAllbridge deregisters CCTP messengers on Arbitrum (05:15 UTC), Base (05:22 UTC), and Polygon (05:28 UTC) and revokes USDC allowances; underlying contract logic not patched.Duplicate of confirmed claim already verified in sections[2].
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.