NewsCryptoCoreum XRPL Bridge Drained of Nearly 200,000 XRP in Deposit Verification Exploit

Coreum XRPL Bridge Drained of Nearly 200,000 XRP in Deposit Verification Exploit

Author: BitcoinKE·

Key Takeaways

  • The Coreum XRPL bridge lost approximately 200,000 XRP across 94 transactions over roughly 97 minutes on August 9, 2026.
  • The attacker exploited a flaw in the bridge's relayer software by attaching fake metadata to internal token transfers so they appeared as valid XRP deposits.
  • The XRP Ledger itself was not compromised, and the bridge was halted immediately after the attack was discovered.
  • Stolen funds were subsequently tracked moving through multiple wallets following the exploit.
  • The incident occurred amid broader market pressure on XRP, which briefly fell below $1 on August 11, 2026, for the first time since late 2024.
Coreum XRPL Bridge Drained of Nearly 200,000 XRP in Deposit Verification Exploit

A cross-chain bridge connected to the XRP Ledger was drained of nearly $200,000 worth of XRP on August 9, 2026, after an attacker exploited a vulnerability in its deposit verification software. The incident highlights ongoing security challenges in infrastructure that connects disparate blockchain networks, a category that has accounted for some of the largest losses in the crypto sector over recent years.

The Coreum XRPL bridge lost approximately 200,000 XRP across 94 transactions executed over roughly 97 minutes, according to blockchain data cited in reports. Prior to the attack, the bridge held about 200,410 XRP. Its balance subsequently dropped to roughly 493.5 XRP.

The attacker did not deposit genuine XRP into the bridge. Instead, they transferred the bridge's own token between wallets while attaching metadata that caused the transactions to appear as legitimate XRP deposits. The bridge's relayer software incorrectly interpreted these transfers as valid incoming XRP and credited the attacker with funds that had never actually been deposited. The attacker was then able to withdraw real XRP from the bridge. This class of vulnerability—manipulating transaction metadata or event logs to trick a bridge's verification logic—has been documented in prior bridge exploits across other ecosystems.

Blockchain tracking data indicates that the stolen funds were subsequently moved through multiple wallets.

The exploit stemmed from a flaw in the bridge's relayer software, not from a compromise of the XRP Ledger itself. The XRP Ledger remained secure throughout the incident. The bridge was halted following the attack.

The incident underscores a persistent vulnerability in cross-chain infrastructure: bridges must independently verify that assets have genuinely been deposited before releasing funds on another network. A failure in that verification layer enables attackers to fabricate balances without needing to compromise the underlying blockchain. High-profile bridge incidents in prior years, including the Ronin Network and Wormhole exploits, collectively resulted in losses exceeding a billion dollars and prompted increased scrutiny of bridge architecture and auditing practices across the industry.

The exploit occurred amid broader market pressure on XRP. On August 11, 2026, the token briefly dropped below $1 for the first time since late 2024, with the bridge exploit contributing to negative sentiment around the asset.

The attack does not indicate that XRP itself was compromised. Rather, it illustrates how vulnerabilities in applications and infrastructure built around major blockchain networks can expose users and liquidity to losses even when the underlying ledger remains fully operational.