Key Takeaways
- A bridge connecting the XRP Ledger to tx suffered a loss of approximately 200,000 XRP, valued at roughly $200,000.
- A software vulnerability enabled the attacker to register fraudulent XRP deposits while bypassing the reserve wallet entirely.
- The security breach spanned approximately 97 minutes on August 9 before operators suspended bridge operations.
- A majority of relayers—17 out of 28—authorized the fund transfers based on falsified deposit data the bridge system validated.
- tx reported patching the compromised code, engaging blockchain forensic experts, and submitting a report to the FBI’s Internet Crime Complaint Center.
A bridge facilitating transfers between the XRP Ledger and tx experienced a significant security breach resulting in the theft of approximately 200,000 XRP. Based on current market valuations, the stolen cryptocurrency amounted to around $200,000, according to statements from the project.
The security incident occurred on August 9, running for roughly 97 minutes until bridge administrators shut down operations. This bridge infrastructure had been serving XRP Ledger participants connecting to Coreum, which underwent a rebrand to tx in March.
Security Weakness Enabled Fraudulent Deposit Records
The perpetrator discovered a method to manipulate the bridge into logging XRP deposits that never actually arrived at the designated reserve wallet. Following these false entries, the system proceeded to mint bridged XRP tokens on the tx blockchain.
The malicious actor subsequently sent back these unbacked tokens via the bridge mechanism, enabling withdrawal of genuine XRP from reserves. This cycle depleted funds that should have remained as collateral for authentic bridged assets.
Under standard operating procedures, the bridge maintains actual XRP holdings in its reserve wallet prior to generating corresponding tokens on the destination chain. Token holders can subsequently redeem these assets to reclaim the reserved XRP.
Majority of Relayers Validated Transactions Per Protocol
The unauthorized drainage commenced at 19:16 UTC. Seventeen relayers among the total 28 participants granted approval for each transaction since the system displayed seemingly legitimate deposit entries in its database.
Relayers function by observing blockchain activity across both networks and authorizing fund movements when the bridge indicates a valid withdrawal request. During this incident, relayers operated according to the corrupted data supplied by the compromised deposit verification system.
tx attributed the fundamental issue to relayer software that accepted payments containing the bridge memo identifier. The programming failed to verify that XRP had actually been transmitted to the proper destination wallet address.
This security gap permitted transactions bearing the correct memo field to register as completed deposits despite transferring zero XRP to the reserve account. The bridge subsequently established token balances without corresponding asset backing.
tx Implements Fix and Engages Law Enforcement
tx reported locating and repairing the compromised code following the suspension of XRP bridge services. The organization additionally retained blockchain forensics professionals to track the misappropriated assets and conduct a comprehensive incident analysis.
The development team submitted an official report to the FBI’s Internet Crime Complaint Center. No announcements have been made regarding compensation arrangements for impacted users or a timeline for resuming bridge functionality.
Blockchain transaction records revealed that the majority of stolen XRP transferred through multiple wallet addresses in the hours following the exploit. Investigation teams maintained surveillance of fund movements as they progressed through these intermediate addresses.





