Key Takeaways
- A bridge connecting the XRP Ledger to the Coreum (tx) blockchain lost approximately 200,000 XRP, valued at roughly $200,000, on August 9
- The exploit centered on a critical software vulnerability that allowed attackers to generate fraudulent deposit records without transferring actual XRP
- Bridge relayers authenticated 94 separate XRP withdrawals spanning 97 minutes based on seemingly legitimate but fabricated transaction data
- Following the attack, the stolen cryptocurrency was rapidly distributed across several wallet addresses
- Operations have been suspended while developers patch the security flaw and authorities investigate the incident
A sophisticated exploit targeting a cross-chain bridge resulted in the theft of approximately 200,000 XRP on August 9, with hackers leveraging a critical software weakness to authorize genuine withdrawals based on counterfeit deposit information.
The compromised infrastructure facilitated transfers between the XRP Ledger and Coreum, a platform that underwent rebranding to tx in March 2024 and specializes in real-world asset tokenization.
Anatomy of the Exploit
Blockchain bridges function as digital custodians with corresponding token systems. When users lock XRP in a reserve address, the bridge mints equivalent wrapped tokens on the destination network. Users can later burn these wrapped tokens to reclaim their original cryptocurrency.
The perpetrator discovered a method to obtain withdrawal authorization without completing legitimate deposits.
The relayer infrastructureāresponsible for monitoring both networks and validating cross-chain transactionsāverified transaction completion status and parsed attached memo fields. However, it failed to confirm whether payments were actually directed to the designated bridge address.
By initiating standard wallet-to-wallet transactions with specially crafted memo fields mimicking authentic bridge deposits, the attacker deceived the relayer system. The software interpreted these transactions as valid deposits and recorded them accordingly.
After achieving consensus among sufficient relayers, the system allocated balances without corresponding XRP reserves. The attacker subsequently initiated standard withdrawal requests to extract genuine XRP from the bridge’s holdings.
Blockchain Evidence
Transaction records reveal 199,916.3 XRP departed the bridge wallet through 94 distinct payments occurring between 19:16 UTC and 20:53 UTC. Prior to the breach, the bridge maintained approximately 200,410 XRP in reserves. Post-attack analysis showed only 493.5 XRP remaining.
Every outbound transaction included 17 signatures from the 28-relayer network, meeting the minimum threshold for authorization. Investigators found no indication of compromised relayer private keys.
Security researchers also dismissed initial speculation regarding the XRP Ledger’s rippling mechanism. This feature exclusively affects issued tokens managed through trust lines. Native XRP operates independently of trust lines, and the entire 199,916 XRP outflow occurred through properly authorized bridge transactions rather than rippling processes.
The vulnerability existed solely within the bridge software implementation, not within either underlying blockchain protocol.
Following the drainage, the stolen assets were swiftly redistributed. Approximately 169,000 XRP transferred to two intermediate wallets established on June 28. An additional 34,000 XRP moved to three separate addresses. Authorities have not yet identified the perpetrator.
According to tx representatives, the team has isolated and remediated the exploited code, engaged blockchain forensics experts, and submitted documentation to the FBI’s Internet Crime Complaint Center.
Bridge operations remain suspended indefinitely. tx has not announced restitution plans for affected users or provided a timeline for service restoration.





