Allbridge Hack
What happened
SlowMist reported an Allbridge exploit on August 19, 2026, affecting roughly $190,000 in the Base router. Its analysis describes a forged CCTP-style message credited as a deposit without a corresponding token burn. This was separate from the July Allbridge Core incident.
Case & protocol details
How it happened
The report describes insufficient validation of an attested cross-chain message. The attacker combined the false deposit credit with temporary liquidity to withdraw real router assets.
Evidence & learning
Proof of concept
1 availableSources and on-chain records
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.