BTC $78,464.39 -0.68%
ETH $2,484.16 -0.01%
BNB $752.43 +1.84%
XRP $1.42 +1.75%
SOL $103.42 -0.22%
TRX $0.3391 +1.43%
DOGE $0.0900 -0.37%
ADA $0.2201 +0.33%
BCH $258.17 +0.02%
LINK $12.53 -1.48%
HYPE $84.99 -0.18%
AAVE $128.99 -2.13%
SUI $0.8111 -0.55%
XLM $0.1880 -2.57%
ZEC $1,181.04 +4.02%
BTC $78,464.39 -0.68%
ETH $2,484.16 -0.01%
BNB $752.43 +1.84%
XRP $1.42 +1.75%
SOL $103.42 -0.22%
TRX $0.3391 +1.43%
DOGE $0.0900 -0.37%
ADA $0.2201 +0.33%
BCH $258.17 +0.02%
LINK $12.53 -1.48%
HYPE $84.99 -0.18%
AAVE $128.99 -2.13%
SUI $0.8111 -0.55%
XLM $0.1880 -2.57%
ZEC $1,181.04 +4.02%

forged

All
Article
Flash

Slow Mist Reveals Details of the Allbridge Cross-Chain Bridge Attack: Forged CCTP Messages, Flash Loans, Insufficient Minting Result Verification

The Slow Mist security team disclosed that the cross-chain bridge project Allbridge was attacked on August 19, 2026, resulting in a loss of approximately $190,000. Notably, this attack was not executed instantly; the attacker had begun laying the groundwork nearly a month prior and bypassed the verification mechanism by forging cross-chain messages. According to Slow Mist's analysis, on July 26, the attacker directly called Circle's MessageTransmitterV2.sendMessage function on the Polygon chain, constructing a cross-chain message disguised as a CCTP style message, claiming that a transfer of 1 million USDC existed, but in reality, no USDC destruction operation took place. Subsequently, Circle generated a valid verification proof (attestation) for this complete message according to normal procedures.About 24 days later, on August 19, the attacker waited for the Base Router to receive a real CCTP deposit, increasing the balance to approximately 191,000 USDC, and initiated the attack just 6 seconds later. The attacker utilized the previously forged message and verification proof to call Allbridge's receiveCctpMessage function. Due to the project's lack of critical verification, the system mistakenly recognized the false cross-chain message as a real deposit and recorded a limit of 1 million USDC. The attacker then temporarily borrowed approximately 809,000 USDC through an Aave flash loan, matching the Router balance with the forged amount, and used the internal credit record to call the transfer function, ultimately transferring out approximately 999,000 USDC (after a 0.1% fee). After repaying the flash loan and fees, the attacker netted a profit of about $189,800. The root cause of this vulnerability lies in Allbridge's failure to verify the identities of the sender and receiver of the cross-chain message, as well as not confirming whether USDC was genuinely minted and whether the balance actually increased, instead directly trusting the amounts and message hash data constructed by the attacker. Slow Mist emphasizes that on-chain message verification does not equate to the actual arrival of real assets. Cross-chain protocols not only need to verify the authenticity of messages but must also ensure that the message source is trustworthy, that the receiver is Circle's official TokenMessengerV2, and that asset accounting can only proceed after confirming the actual minting of assets and changes in balance. This incident once again highlights the security risks of cross-chain bridges in the message verification and asset settlement processes.

The Hong Kong Securities and Futures Commission enhances measures to combat forged documents and money laundering risks and raises account opening standards

The Hong Kong Securities and Futures Commission (SFC) issued a circular outlining the monitoring measures that should be implemented when opening accounts and maintaining client relationships. This circular was issued after the SFC reviewed the account opening practices of 12 securities brokerage firms.The review identified several significant deficiencies, including insufficient due diligence on account opening documents, acceptance of suspicious or forged documents during the account opening process, and weaknesses in managing cross-border agency relationships with overseas intermediaries. The SFC expressed deep concern about the potential misuse of client accounts for suspicious or illegal transactions, which could exacerbate the risks of money laundering and terrorist financing.The SFC requires all licensed corporations to conduct internal checks as soon as practicable to detect whether any suspicious or forged documents have been accepted for account opening. The SFC also outlined additional measures for licensed corporations when opening and managing accounts for mainland investors.These additional measures include closing investment accounts opened with suspicious or forged documents, closing zero-balance dormant investment accounts, and requiring a written declaration from investors when opening new investment accounts, stipulating that settlements and fund withdrawals can only be conducted through bank accounts held in the investor's own name at qualified banks.

The main culprit of the Meta-1 Coin scam has been sentenced to 23 years in prison, having claimed a return rate of 224923% and forged a gold reserve of 44 billion dollars

According to Forbes, a U.S. court sentenced Robert Dunlap, the operator of the cryptocurrency scam Meta-1 Coin, to 23 years in prison. He was accused of defrauding approximately 1,000 investors through a fraudulent cryptocurrency investment project from 2018 to 2023, with the amount involved exceeding $20 million.According to the U.S. Department of Justice, Dunlap claimed that the "Meta-1 Coin" he issued was backed by $44 billion in gold reserves and $1 billion worth of artworks by Picasso, Dali, Van Gogh, etc., and promised a maximum return rate of 224,923%, while providing investors with forged audit documents and insurance materials.Investigations revealed that the so-called gold and art assets did not exist, and the "Meta Exchange" website he built used automated trading bots to create the illusion of profits. The related tokens were never actually issued on-chain. Investor funds were subsequently used to purchase luxury items, including Ferraris.It is worth noting that the U.S. Securities and Exchange Commission had already filed a civil fraud lawsuit against Dunlap in 2020, but he continued to operate the project until he was criminally charged in 2024. The FBI stated that the case "destroyed the wealth and trust accumulated by many victims over the years."
app_icon
ChainCatcher Building the Web3 world with innovations.