Key Takeaways
- A bridge connecting XRP Ledger to the Coreum (now tx) blockchain suffered a loss of approximately 200,000 XRP, valued at roughly $200,000, during an attack on August 9
- The exploit stemmed from a critical software vulnerability that allowed the creation of fraudulent deposit entries without actual XRP transfers to the bridge
- Bridge relayers validated what appeared to be legitimate transaction records, approving 94 authentic XRP withdrawals spanning 97 minutes
- The compromised funds were rapidly dispersed across several wallets in the hours following the incident
- Operations have been suspended, the security flaw has been patched, and authorities including the FBI have been contacted
A sophisticated attack on August 9 resulted in the theft of nearly 200,000 XRP from a blockchain bridge by taking advantage of a critical software vulnerability that mistakenly processed fabricated deposits as genuine transactions.
An update on the XRPL bridge incident.
On August 9, the tx XRPL bridge was exploited and XRP was drained from the bridge’s reserve wallet on the XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. Thisā¦
ā tx (@txEcosystem) August 11, 2026
The compromised infrastructure facilitated transfers between the XRP Ledger and Coreum, a blockchain platform that underwent rebranding to tx in March and specializes in tokenization of tangible assets.
Anatomy of the Exploit
Blockchain bridges function similarly to escrow systems with proof-of-deposit mechanisms. Users lock XRP in a designated reserve wallet, and the bridge mints corresponding wrapped tokens on the destination chain. Users can later redeem these tokens to reclaim their original XRP.
The perpetrator discovered a method to obtain redemption proofs without actually depositing funds.
The relayer infrastructure, responsible for monitoring both blockchains and validating transfers, verified transaction success and parsed attached memo fields. However, it critically failed to confirm whether funds were actually directed to the bridge’s designated address.
By executing wallet-to-wallet transactions with carefully crafted memos mimicking legitimate bridge deposit formats, the attacker fooled the relayers. The system interpreted these transactions as valid deposits and recorded them accordingly.
After achieving consensus among sufficient relayers, the bridge credited balances without corresponding XRP reserves. The attacker subsequently exploited the standard withdrawal mechanism to extract genuine XRP from the bridge’s holdings.
Blockchain Evidence
On-chain forensics revealed 199,916.3 XRP exiting the bridge’s account via 94 separate transactions between 19:16 UTC and 20:53 UTC. Prior to the incident, the bridge maintained approximately 200,410 XRP in reserves. Following the attack, merely 493.5 XRP remained.
Every outbound transaction bore 17 signatures from the 28-member relayer pool, satisfying the required threshold. Investigators found no indication of compromised relayer credentials.
Forensic experts also dismissed initial speculation regarding the XRP Ledger’s rippling mechanism. This feature pertains to issued tokens managed via trust lines. Native XRP operates independently of trust lines, and the entire 199,916 XRP was withdrawn through properly signed bridge transactions rather than rippling processes.
The vulnerability existed solely in the bridge software layer, not in either underlying blockchain protocol.
Following the theft, the stolen assets were swiftly redistributed. Approximately 169,000 XRP flowed into two intermediary wallets established on June 28. An additional 34,000 XRP was transferred to three separate addresses. The perpetrator’s identity remains unknown.
According to tx, the vulnerable code has been isolated and remediated, blockchain forensics experts have been retained, and a formal complaint has been submitted to the FBI’s Internet Crime Complaint Center.
The bridge infrastructure continues to remain offline. tx has yet to announce compensation plans for impacted users or provide a timeline for resuming operations.


