← Allbridge1 decision on this page
Audit log
Every state-changing event for Allbridge: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-30 17:10:35ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
8LNSJ88dC7vW…rxdPVoZXsha256 → base58
verifying row…canonical bytes (21406 B) ▸
{"actor":"system:backfill","investigation_id":"c2440c5d-c86e-4b7d-bb6a-f3a485c94fe2","kind":"publish","page_slug":"allbridge","published_at":"2026-08-30T17:10:35.153Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Allbridge","sections":[{"content":"Allbridge launched in July 2021 under the name Solbridge, initially focused on connecting Solana to other blockchain networks. The project subsequently expanded into two main products: Allbridge Classic, supporting token bridging across more than 20 EVM and non-EVM chains, and Allbridge Core, launched in June 2022, focused on cross-chain stablecoin swaps. The protocol is part of Circle's Cross-Chain Transfer Protocol (CCTP) Alliance Program. Allbridge is headquartered in Kyiv, Ukraine, and was founded by Andriy Velykyy. The project's native token, ABR, has a total supply of 100 million tokens. Security audits have been conducted by Hacken, Kudelski Security, Cossack Labs, and CoinFabrik, with the CoinFabrik audit finding no critical issues at the time of review.","heading":"Protocol Overview","severity":"low","sources":[{"credibility":2,"name":"Allbridge — A Deep Dive (LI.FI)","type":"research","url":"https://li.fi/knowledge-hub/allbridge-a-deep-dive"},{"credibility":1,"name":"Allbridge company page","type":"official","url":"https://allbridge.io/company/"},{"credibility":2,"name":"Allbridge audits by Hacken","type":"research","url":"https://hacken.io/audits/allbridge/"},{"credibility":1,"name":"Security audit — Allbridge Core (official docs)","type":"official","url":"https://docs-core.allbridge.io/product/security-audit"}]},{"content":"On April 1–2, 2023, Allbridge Core's BNB Chain pools were exploited for approximately $570,000 through a flash loan attack. The attacker manipulated the protocol's internal swap pricing by acting simultaneously as a liquidity provider and swapper, borrowing a large sum to artificially distort the USDC/USDT pool ratio and withdrawing funds at favorable manufactured rates. The stolen funds comprised approximately $289,900 in BUSD and $290,900 in USDT. Allbridge paused the protocol, contacted the attacker on-chain with a white-hat bounty offer, and subsequently recovered approximately $465,000 of the stolen amount after the attacker accepted the arrangement. Allbridge published a post-mortem in May 2023 committing to a structural fix: deploying a single liquidity pool per blockchain to make same-transaction flash loan manipulation structurally impossible, and adding withdrawal caps tied to LP token balances. A compensation plan for affected liquidity providers was also announced.","heading":"April 2023 Flash Loan Exploit (BNB Chain, ~$573K)","severity":"high","sources":[{"credibility":2,"name":"Allbridge Exploit: Hacker Returns Majority Of $573K Stolen Funds — BitcoinWorld","type":"news_article","url":"https://bitcoinworld.co.in/allbridge-exploiter-returns-most-of-the-573k-stolen-in-attack/"},{"credibility":2,"name":"Allbridge Recovers $465,000 Stolen in Crypto Exploit — Blockchain.news","type":"news_article","url":"https://blockchain.news/news/allbridge-recovers-465-000-stolen-in-crypto-exploit"},{"credibility":2,"name":"Allbridge Provides Compensation Plan for Hacked Users — Blockchain.news","type":"news_article","url":"https://blockchain.news/news/allbridge-provides-compensation-plan-for-hacked-users"},{"credibility":2,"name":"Allbridge Hack Response: Bridge Locked, White Hat Bounty, LPs Opened for Withdrawals — CryptoNews","type":"news_article","url":"https://cryptonews.net/news/security/20754571/"}]},{"content":"On July 19, 2026, Allbridge Core suffered a second flash loan exploit, this time targeting its Solana deployment. The attacker borrowed approximately $1.12 million USDC from Kamino Finance on Solana, used those funds to distort the USDC/USDT pool ratio in Allbridge's pools, then withdrew liquidity at the artificially inflated rate before repaying the loan — netting approximately $1.65 million. The stolen assets were bridged from Solana to Ethereum and partially routed through privacy pools. According to reporting by CryptoComes and Startup Fortune, the attack was structurally identical to the April 2023 BNB Chain incident. The 2023 post-mortem committed to deploying a single liquidity pool per blockchain as the primary structural defense; however, reporting indicates the Solana deployment was not updated with the equivalent protections, allowing the same vulnerability class to be exploited again. PeckShield identified the exploit. Allbridge paused operations and asked arbitrageurs who had profited from the resulting pool imbalance to voluntarily return funds to a recovery address. As of available reporting, no formal compensation guarantee was issued for the July 2026 incident.","heading":"July 2026 Flash Loan Exploit (Solana, ~$1.65M) — Repeat Vulnerability","severity":"critical","sources":[{"credibility":1,"name":"Cross-chain protocol Allbridge halts after $1.65 million flash loan exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/20/cross-chain-protocol-allbridge-halts-after-usd1-65-million-flash-loan-exploit"},{"credibility":2,"name":"Allbridge Core Hit by $1.65M Solana Flash-Loan Exploit, Its Second Since 2023 — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/20/allbridge-core-hit-by-1-65m-solana-flash-loan-exploit-its-second-since-2023/"},{"credibility":2,"name":"Allbridge Core Loses $1.65 Million to the Same Flash Loan Trick Twice — Startup Fortune","type":"news_article","url":"https://startupfortune.com/allbridge-core-loses-165-million-to-the-same-flash-loan-trick-twice/"},{"credibility":2,"name":"Allbridge Flash Loan Attack Drains $1.65M — For the Second Time — CryptoComes","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/20/allbridge-flash-loan-attack/"},{"credibility":2,"name":"Allbridge Core halted after $1.65M Solana exploit — Crypto.news","type":"news_article","url":"https://crypto.news/allbridge-core-halted-after-1-65m-solana-exploit/"},{"credibility":2,"name":"Allbridge Core Exploit on Solana — Web3 Is Going Just Great","type":"community_report","url":"https://www.web3isgoinggreat.com/single/allbridge-exploit"}]},{"content":"On August 19, 2026, Allbridge's Base chain CCTP router was exploited for approximately $191,000 in USDC through a sophisticated cross-chain attack that was prepared approximately 24 days in advance. According to SlowMist's post-mortem analysis, the attacker began the attack on July 26, 2026, by directly calling Circle's MessageTransmitterV2.sendMessage function on Polygon, constructing a forged CCTP-format message that falsely claimed a transfer of 1 million USDC — without any actual USDC burn occurring. Circle's standard attestation infrastructure subsequently generated a valid cryptographic attestation for this message, as the attestation process verified the message format but did not independently confirm that a token burn had occurred. On August 19, the attacker monitored Allbridge's Base Router until a legitimate CCTP deposit brought its balance to approximately 191,000 USDC. Within six seconds of that deposit landing, the attacker invoked Allbridge's receiveCctpMessage function using the pre-staged forged message with its valid attestation. Because Allbridge's implementation did not verify: (1) the identity of the message sender, (2) whether the claimed amount corresponded to an actual USDC mint from Circle's official TokenMessengerV2, or (3) whether the router's balance had actually increased by the stated amount — the protocol credited 1 million USDC to the attacker. The attacker then used an Aave flash loan of approximately 809,000 USDC to cover the difference and withdrew approximately 999,000 USDC from the router, draining its entire balance. After repaying the flash loan and fees, the net loss to the protocol was approximately $191,000. SlowMist's analysis concluded that the core flaw was that Allbridge 'blindly trusted the amount and message hash data provided by the attacker' without independently verifying that assets were actually minted or that the message originated from a trusted source. SlowMist further noted that this class of verification failure could enable substantially larger attacks on higher-liquidity router deployments, and recommended that cross-chain protocols integrating CCTP must verify: message origin from Circle's official TokenMessengerV2, actual on-chain mint confirmation, and balance changes before crediting any assets.","heading":"August 2026 CCTP Router Exploit (Base, ~$191K) — Forged Circle Attestation","severity":"critical","sources":[{"credibility":2,"name":"A Cross-Chain Attack Spanning One Month: Analysis of the Allbridge Hack — SlowMist on Medium","type":"research","url":"https://slowmist.medium.com/a-cross-chain-attack-spanning-one-month-analysis-of-the-allbridge-hack-32a6183bce08"},{"credibility":2,"name":"SlowMist Reveals Allbridge Attack Details: Fake CCTP Messages, Flash Loans, and Insufficient Minting Verification — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/slow-mist-reveals-allbridge-cross-chain-bridge-attack-details-fake-cctp-messages-flash-loans-and-insufficient-minting-verification"},{"credibility":2,"name":"Crypto Hacks Drain $15M in a Week — CryptoTimes (August 2026)","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/crypto-hacks-drain-15m-in-a-week-as-maya-bouncebit-sandbox-and-term-labs-fall/"}]},{"content":"Across three separate incidents spanning April 2023 to August 2026, Allbridge has suffered security losses totaling approximately $2.41 million (before recoveries). Two of the three incidents involved a structurally identical flash loan price manipulation vector, with the second occurrence in July 2026 reportedly succeeding because the remediation committed to in the 2023 post-mortem was applied to some but not all chain deployments — specifically, the Solana deployment was allegedly left unpatched. The third incident in August 2026 involved a distinct attack class — forged CCTP attestation messages — but similarly exploited missing validation logic in the protocol's receiving contract. SlowMist's post-mortem characterized the August 2026 vulnerability as systemic, warning that equivalent CCTP validation gaps in higher-liquidity deployments could enable materially larger losses. The recurrence of exploitable vulnerabilities across different deployments of the same protocol, following public post-mortems committing to architectural remediation, raises concerns about the thoroughness of cross-chain security review processes at Allbridge. These are security failures experienced by the protocol; Allbridge is the victim in each incident, not the perpetrator. However, the pattern is relevant to users and liquidity providers assessing ongoing risk exposure.","heading":"Pattern of Systemic Security Failures","severity":"high","sources":[{"credibility":2,"name":"A Cross-Chain Attack Spanning One Month: Analysis of the Allbridge Hack — SlowMist on Medium","type":"research","url":"https://slowmist.medium.com/a-cross-chain-attack-spanning-one-month-analysis-of-the-allbridge-hack-32a6183bce08"},{"credibility":2,"name":"Allbridge Core Loses $1.65 Million to the Same Flash Loan Trick Twice — Startup Fortune","type":"news_article","url":"https://startupfortune.com/allbridge-core-loses-165-million-to-the-same-flash-loan-trick-twice/"},{"credibility":2,"name":"Allbridge Core Loses $1.65M to Flash Loan Again After Its Single-Pool Fix Missed Solana — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/321044/20260720/allbridge-core-loses-165m-flash-loan-again-after-its-single-pool-fix-missed-solana.htm"}]},{"content":"Following the April 2023 exploit, Allbridge negotiated a white-hat arrangement and recovered approximately $465,000 of the $573,000 stolen, and issued a compensation plan for affected liquidity providers. Following the July 2026 exploit, Allbridge paused the protocol and appealed publicly to arbitrageurs who had profited from the distorted pool to voluntarily return funds; no formal compensation guarantee was publicly announced as of available reporting. Following the August 2026 CCTP exploit, Allbridge paused cross-chain operations. The current operational status of the protocol and whether it has resumed after patching the August 2026 CCTP vulnerability is not confirmed in available sources as of this writing. Allbridge continues to be listed as a participant in Circle's CCTP Alliance Program.","heading":"Protocol Status and Recovery History","severity":"medium","sources":[{"credibility":2,"name":"Allbridge Recovers $465,000 Stolen in Crypto Exploit — Blockchain.news","type":"news_article","url":"https://blockchain.news/news/allbridge-recovers-465-000-stolen-in-crypto-exploit"},{"credibility":2,"name":"Allbridge pauses cross-chain bridge after $1.65M exploit — LCX","type":"news_article","url":"https://lcx.com/en/cryptonews/allbridge-pauses-cross-chain-bridge-after-165m-exploit"},{"credibility":2,"name":"Allbridge Core Pauses Bridge After $1.66M Solana Flash Loan Exploit — NFT Evening","type":"news_article","url":"https://nftevening.com/allbridge-core-pauses-bridge-after-1-66m-solana-flash-loan-exploit/"}]}],"sources_used":[{"credibility":2,"name":"Allbridge — A Deep Dive (LI.FI Knowledge Hub)","type":"research","url":"https://li.fi/knowledge-hub/allbridge-a-deep-dive"},{"credibility":1,"name":"Allbridge company page","type":"official","url":"https://allbridge.io/company/"},{"credibility":2,"name":"A Cross-Chain Attack Spanning One Month: Analysis of the Allbridge Hack — SlowMist","type":"research","url":"https://slowmist.medium.com/a-cross-chain-attack-spanning-one-month-analysis-of-the-allbridge-hack-32a6183bce08"},{"credibility":2,"name":"SlowMist Reveals Allbridge Attack Details: Fake CCTP Messages, Flash Loans, Insufficient Minting Verification — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/slow-mist-reveals-allbridge-cross-chain-bridge-attack-details-fake-cctp-messages-flash-loans-and-insufficient-minting-verification"},{"credibility":1,"name":"Cross-chain protocol Allbridge halts after $1.65 million flash loan exploit — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/07/20/cross-chain-protocol-allbridge-halts-after-usd1-65-million-flash-loan-exploit"},{"credibility":2,"name":"Allbridge Core Hit by $1.65M Solana Flash-Loan Exploit, Its Second Since 2023 — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/20/allbridge-core-hit-by-1-65m-solana-flash-loan-exploit-its-second-since-2023/"},{"credibility":2,"name":"Allbridge Core Loses $1.65 Million to the Same Flash Loan Trick Twice — Startup Fortune","type":"news_article","url":"https://startupfortune.com/allbridge-core-loses-165-million-to-the-same-flash-loan-trick-twice/"},{"credibility":2,"name":"Allbridge Core Loses $1.65M to Flash Loan Again After Its Single-Pool Fix Missed Solana — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/321044/20260720/allbridge-core-loses-165m-flash-loan-again-after-its-single-pool-fix-missed-solana.htm"},{"credibility":2,"name":"Allbridge Flash Loan Attack Drains $1.65M — For the Second Time — CryptoComes","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/20/allbridge-flash-loan-attack/"},{"credibility":2,"name":"Allbridge Core halted after $1.65M Solana exploit — Crypto.news","type":"news_article","url":"https://crypto.news/allbridge-core-halted-after-1-65m-solana-exploit/"},{"credibility":2,"name":"Allbridge Exploit — Web3 Is Going Just Great","type":"community_report","url":"https://www.web3isgoinggreat.com/single/allbridge-exploit"},{"credibility":2,"name":"Allbridge Exploit: Hacker Returns Majority Of $573K Stolen Funds — BitcoinWorld","type":"news_article","url":"https://bitcoinworld.co.in/allbridge-exploiter-returns-most-of-the-573k-stolen-in-attack/"},{"credibility":2,"name":"Allbridge Recovers $465,000 Stolen in Crypto Exploit — Blockchain.news","type":"news_article","url":"https://blockchain.news/news/allbridge-recovers-465-000-stolen-in-crypto-exploit"},{"credibility":2,"name":"Allbridge Provides Compensation Plan for Hacked Users — Blockchain.news","type":"news_article","url":"https://blockchain.news/news/allbridge-provides-compensation-plan-for-hacked-users"},{"credibility":2,"name":"Allbridge Hack Response: Bridge Locked, White Hat Bounty — CryptoNews","type":"news_article","url":"https://cryptonews.net/news/security/20754571/"},{"credibility":2,"name":"Crypto Hacks Drain $15M in a Week — CryptoTimes (August 2026)","type":"news_article","url":"https://www.cryptotimes.io/2026/08/24/crypto-hacks-drain-15m-in-a-week-as-maya-bouncebit-sandbox-and-term-labs-fall/"},{"credibility":2,"name":"Allbridge audits by Hacken","type":"research","url":"https://hacken.io/audits/allbridge/"},{"credibility":2,"name":"Allbridge pauses cross-chain bridge after $1.65M exploit — LCX","type":"news_article","url":"https://lcx.com/en/cryptonews/allbridge-pauses-cross-chain-bridge-after-165m-exploit"}],"summary":"Allbridge is a cross-chain bridging protocol founded in 2021 that operates Allbridge Classic and Allbridge Core, supporting stablecoin transfers across more than 20 blockchains. The protocol has suffered three separate security incidents since its launch: a $573K flash loan exploit on BNB Chain in April 2023, a $1.65M flash loan attack on its Solana deployment in July 2026, and a $191K CCTP router exploit on Base in August 2026 involving forged Circle attestation messages. The recurrence of similar vulnerability classes across deployments — and the failure to apply 2023 remediations to all active chains — raises systemic concerns about the protocol's security review and deployment practices.","timeline":[{"date":"2021-07-01","event":"Allbridge (originally named Solbridge) launches, focused on connecting Solana to other blockchain networks.","source":"LI.FI Knowledge Hub — Allbridge Deep Dive","source_url":"https://li.fi/knowledge-hub/allbridge-a-deep-dive"},{"date":"2022-06-01","event":"Allbridge Core launches as a dedicated cross-chain stablecoin swap platform.","source":"LI.FI Knowledge Hub — Allbridge Deep Dive","source_url":"https://li.fi/knowledge-hub/allbridge-a-deep-dive"},{"date":"2023-04-01","event":"Allbridge Core's BNB Chain pools exploited for approximately $573K via flash loan price manipulation. Attacker drained ~$289,900 BUSD and ~$290,900 USDT.","source":"BitcoinWorld — Allbridge Exploit: Hacker Returns Majority Of $573K Stolen Funds","source_url":"https://bitcoinworld.co.in/allbridge-exploiter-returns-most-of-the-573k-stolen-in-attack/"},{"date":"2023-04-03","event":"Allbridge contacts attacker on-chain offering a white-hat bounty; attacker eventually returns approximately $465,000.","source":"Blockchain.news — Allbridge Recovers $465,000 Stolen in Crypto Exploit","source_url":"https://blockchain.news/news/allbridge-recovers-465-000-stolen-in-crypto-exploit"},{"date":"2023-05-01","event":"Allbridge publishes post-mortem committing to single-liquidity-pool-per-blockchain architecture and withdrawal caps to prevent flash loan attacks.","source":"CryptoNews — Allbridge Hack Response","source_url":"https://cryptonews.net/news/security/20754571/"},{"date":"2026-07-19","event":"Allbridge Core's Solana deployment exploited for approximately $1.65M via flash loan attack using Kamino Finance. Same vulnerability class as 2023 BNB Chain incident; the Solana deployment was reportedly not updated with the 2023 remediation.","source":"CoinDesk — Cross-chain protocol Allbridge halts after $1.65 million flash loan exploit","source_url":"https://www.coindesk.com/business/2026/07/20/cross-chain-protocol-allbridge-halts-after-usd1-65-million-flash-loan-exploit"},{"date":"2026-07-26","event":"Attacker prepares August 2026 CCTP exploit by calling Circle's MessageTransmitterV2.sendMessage on Polygon, forging a CCTP message claiming a 1 million USDC transfer without any actual burn. Circle generates a valid attestation for the message.","source":"SlowMist — A Cross-Chain Attack Spanning One Month","source_url":"https://slowmist.medium.com/a-cross-chain-attack-spanning-one-month-analysis-of-the-allbridge-hack-32a6183bce08"},{"date":"2026-08-19","event":"Attacker executes the CCTP exploit on Allbridge's Base Router, draining approximately $191,000 in USDC. Attack leverages the pre-forged Polygon attestation and an Aave flash loan. Root cause: missing sender-identity, message-origin, and mint-amount verification in the receiveCctpMessage function.","source":"KuCoin — SlowMist Reveals Allbridge Cross-Chain Bridge Attack Details","source_url":"https://www.kucoin.com/news/flash/slow-mist-reveals-allbridge-cross-chain-bridge-attack-details-fake-cctp-messages-flash-loans-and-insufficient-minting-verification"},{"date":"2026-08-01","event":"SlowMist publishes detailed post-mortem of the August 2026 CCTP exploit, flagging systemic cross-chain verification failures and warning of potential for larger attacks on higher-liquidity deployments.","source":"SlowMist on Medium — A Cross-Chain Attack Spanning One Month","source_url":"https://slowmist.medium.com/a-cross-chain-attack-spanning-one-month-analysis-of-the-allbridge-hack-32a6183bce08"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 04b57dff-292c-4044-8600-b706609d4634
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.