NewsCryptoXRP Bridge Drained of $200,000 After Software Flaw Registered Fake Deposits as Real

XRP Bridge Drained of $200,000 After Software Flaw Registered Fake Deposits as Real

Author: Coindesk·

Key Takeaways

  • Nearly 200,000 XRP worth approximately $200,000 was stolen from a cross-chain bridge between the XRP Ledger and the tx blockchain on August 9.
  • The exploit targeted a software vulnerability where relayer code processed transactions carrying the bridge's memo field without verifying the destination address, treating fictitious deposits as legitimate.
  • The attack lasted approximately 97 minutes, with a majority of the bridge's 28 relayers authorizing each payout because the bridge's own records indicated valid deposits.
  • tx has patched the vulnerable code, engaged blockchain forensics specialists, and filed a complaint with the FBI's Internet Crime Complaint Center, but has not yet announced how affected holders will be compensated.
  • On-chain tracking indicates the stolen XRP was quickly dispersed across multiple wallets, a pattern commonly used to obscure fund trails and complicate recovery efforts.
XRP Bridge Drained of $200,000 After Software Flaw Registered Fake Deposits as Real

XRP Bridge Drained of $200,000 After Software Flaw Registered Fake Deposits as Real

Nearly 200,000 XRP — worth approximately $200,000 at current prices — were drained from a cross-chain bridge linking the XRP Ledger to the tx blockchain on August 9, after an attacker exploited a software vulnerability that allowed non-existent deposits to be recorded as genuine. The incident adds to a long history of cross-chain bridge exploits, which have collectively cost the crypto industry billions of dollars and remain one of the most targeted categories of decentralized finance infrastructure.

The bridge connected the XRP Ledger to Coreum, a blockchain that rebranded this March as tx, a U.S.-based project focused on tokenizing real-world assets. According to tx, the bridge's software incorrectly recognized certain transactions as deposits even though they never delivered any XRP to the bridge's reserve wallet. This allowed the attacker to mint unbacked bridged XRP on the tx chain, then send those tokens back through the bridge to withdraw real XRP from the reserve.

The drain began at 19:16 UTC and lasted approximately 97 minutes before the system was halted. Each payout was authorized by 17 of the bridge's 28 relayers — a majority — signing off exactly as designed, because the bridge's own records indicated the deposits were legitimate. Relayers are programs that monitor both blockchains and approve transfers when the bridge's ledger shows a withdrawal is owed.

The specific failure, however, lay one layer deeper. The relayer code processed payments carrying the bridge's memo without first verifying the destination address, meaning transactions that included the correct memo field but directed XRP elsewhere were still treated as valid deposits. This class of input-validation flaw — where bridge software trusts a field like a memo or identifier without confirming the actual transfer of funds — has surfaced in other bridge exploits across the industry, where attackers have repeatedly manipulated proof or messaging systems to convince bridges that deposits occurred when they did not.

How the Bridge Was Supposed to Work

A bridge functions like a vault with a receipt system. A user sends XRP into a reserve wallet on the XRP Ledger, and the bridge creates an equivalent amount of bridged XRP on the destination chain. When the user returns those bridged tokens, they can withdraw the corresponding real XRP from the reserve. The attacker effectively found a way to make the system issue receipts without depositing anything into the vault.

Response and Investigation

tx confirmed the deposit-detection flaw in a public update, stating that the attacker exploited software that incorrectly recognized transactions delivering no XRP to the reserve as valid deposits.

The project said it has identified and patched the vulnerable code, engaged blockchain forensics specialists, and filed a complaint with the FBI's Internet Crime Complaint Center (IC3) — a step commonly taken by crypto projects after exploits, though recovery rates for stolen digital assets remain low. However, tx has not yet disclosed how affected holders will be compensated.

An update on the XRPL bridge incident. On August 9, the tx XRPL bridge was exploited and XRP was drained from the bridge's reserve wallet on the XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. This… — tx (@txEcosystem) August 11, 2026

Meanwhile, on-chain tracking indicates that most of the stolen XRP did not remain in a single wallet. Within hours, the funds moved onward through several other addresses, complicating recovery efforts — a pattern frequently observed following crypto exploits, where attackers attempt to obscure fund trails across multiple wallets and exchanges.