Allbridge was attacked on Aug. 19, 2026, with losses of about $190,000 after an attacker exploited gaps in its cross-chain message and asset-settlement controls. Nearly a month earlier, on July 26, the attacker called Circle’s MessageTransmitterV2.sendMessage function directly on Polygon to create a forged CCTP-style message claiming a transfer of 1 million USDC, even though no USDC had been burned. Circle subsequently issued a valid attestation for the complete message through its normal process. About 24 days later, the attacker waited until Base Router received a genuine CCTP deposit and its balance rose to about 191,000 USDC. Six seconds later, the attacker used the forged message and attestation to call Allbridge’s receiveCctpMessage function. Because Allbridge lacked key checks, it treated the false message as a genuine deposit and recorded a 1 million USDC credit. The attacker then borrowed about 809,000 USDC through an Aave flash loan, a temporary loan repaid within the same transaction, to make the Router balance match the forged amount. Using the internal credit record, the attacker called the transfer function and moved about 999,000 USDC after a 0.1% fee. After repaying the flash loan and associated costs, the net gain was about $189,800. SlowMist said the root cause was Allbridge’s failure to verify the identities of the message sender and recipient, confirm that USDC had actually been minted, and establish that the balance had genuinely increased. The incident underscores that validating an on-chain message does not prove that assets arrived. Cross-chain protocols must also verify a trusted source, ensure that the recipient is Circle’s official TokenMessengerV2, and confirm actual asset minting and balance changes before recording funds.