Allbridge Hack

ESTIMATED LOSS $191K
Low Cross-Chain Message Validation Flaw base

What happened

SlowMist reported an Allbridge exploit on August 19, 2026, affecting roughly $190,000 in the Base router. Its analysis describes a forged CCTP-style message credited as a deposit without a corresponding token burn. This was separate from the July Allbridge Core incident.

Case & protocol details

Classification Bridge & Cross-Chain
Implementation language Solidity
Official Website allbridge.io/
Protocol Twitter/X @Allbridge_io

How it happened

The report describes insufficient validation of an attested cross-chain message. The attacker combined the false deposit credit with temporary liquidity to withdraw real router assets.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.