← Radar

Incident case file

Sign in to watch

Allbridge Phantom CCTP Deposit Exploit — Base Router Drain

Incident date 2026-07-24Last updated Aug 26, 2026

0 views

ContainedBaseBridge logic flaw — phantom CCTP deposit (forged Circle attestation credited without balance verification)Cluster: ABR-CCTP-2026-08

Estimated loss

$191.2K

Victims identified

1
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Ledger

Attacker

0x2419432344b0b892e592b2601b98eae702ba360e (EOA, doubly confirmed by independent Defimon and SlowMist post-mortems). Copycat: 0xf33f35046afd68eD900A3C7fbd9a1828d2464da0.

Funds moved to

Net 189,752 USDC withdrawn to the attacker's EOA at 06:28:35 UTC (an EIP-7702 account delegated to MetaMask's smart account), then swapped through Jumper and Mayan Swift between 06:34-06:37 UTC into approximately 99 ETH on Ethereum, held at the same address and unmoved since. A copycat drained the residual ~1,000 USDC fee balance in two follow-up transactions within 25-59 minutes of the original attack.

Linked

Exploit harness contract: 0xb6fBDFA5F3CBEB139D4ccE86D92F4ac8687B16c0. Exploit logic contract: 0xe9edf1582ed9520f7149669d9c6bf3276b02477e. Victim (Allbridge Base router): 0xaA119F7442Ecc28b9a8f236707aDa8362cFF24fF. Vulnerable CCTPTokenMessenger: 0xf9b710E427bf4d93598e0F80A84dE22C7Ad9b577. Allbridge relayer: 0x58831c11adC30de780Ba6ac7B9a593600ae75E2E. Allbridge owner (deregistration): 0x6588FB6e92d9fa540534e7920E07F9c8627a4Ce1. The attacker funded the exploit via an Aave flash loan of 808,844 USDC

Chronology

1 beat
  1. Jul 25/26, 2026, 20:32:55 UTC: Attacker calls Circle's MessageTransmitterV2.sendMessage on Polygon (tx 0x2a88d79756b4547b33fea7b3c1420793680e2b8952bef4c65e99879e16b22140), constructing a forged CCTP-style message declaring a 1,000,000 USDC transfer with no actual USDC burned. Circle's attestation service signs the message as authentic, since it only verifies the message content was not tampered with — not that a mint actually occurred. The message sits attested for 24 days. Aug 19, 01:47:11 UTC (block 50157342): A legitimate CCTP deposit from another user mints ~191,112 USDC into Allbridge's Base router, bringing its balance to ~191,156 USDC. Aug 19, 01:47:17 UTC (block 50157345, six seconds later): Attacker's transaction 0x9f906fcd8fceaa6745e8d1c004861dcfa9b5e6a893fe1e8c5d0013a4e982e6a8 redeems the forged message via CCTPTokenMessenger.receiveCctpMessage. The contract lacks checks on the message sender (should equal the remote TokenMessenger) and recipient (should equal Circle's TokenMessengerV2), so it credits the fabricated 1,000,000 USDC as a real deposit without confirming any balance increase. An Aave flash loan tops the router to the declared figure; Router.receiveToken pays out 999,000 USDC after a 0.1% fee. Attacker repays the flash loan plus premium, netting 189,752 USDC — draining the router's entire balance, most of which belonged to the in-flight legitimate deposit. 02:12-02:46 UTC: A copycat (0xf33f3504...) reproduces the exploit twice within 25-59 minutes, draining the router's residual ~1,000 USDC fee balance down to $0.001. 05:15:52-09:31:00 UTC: Allbridge's owner deregisters the CCTP and LayerZero OFT messengers across Base, Polygon, and Arbitrum as a kill switch (not a code fix); receiveCctpMessage itself remains unpatched. 06:28:35-06:37 UTC: Attacker withdraws and launders proceeds into ~99 ETH, unmoved since. Aug 22, 2026: SlowMist independently publishes a fully convergent post-mortem ('A Cross-Chain Attack Spanning One Month'), confirming Defimon's technical reconstruction and recommending that redeemable deposits only be created after an observed balance increase. As of publication, Allbridge has issued no official public statement about the incident.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)