XRPL-tx Bridge Exploited for 200,000 XRP Through Fake Deposit Vulnerability
Key Takeaways
- β’Approximately 200,000 XRP (roughly $200,000) was stolen on August 9 through an exploit of a deposit detection flaw in the XRPL-tx cross-chain bridge.
- β’The vulnerability allowed the attacker to mint unbacked bridged XRP and use those fabricated balances to withdraw real XRP from the bridge's reserve, despite the bridge having passed multiple internal and third-party security audits before launch.
- β’The impact was limited to bridged XRP on the tx chain, which is no longer backed one-to-one by actual XRP reserves, while other bridged assets and user funds on exchanges or blockchains remained unaffected.
- β’The tx team has shut down the bridge, applied code fixes, filed a formal complaint with the FBI Internet Crime Complaint Center, and is collaborating with blockchain forensics firms to track the stolen funds.
- β’The XRPL-tx bridge will remain suspended until all security reviews and system upgrades are completed, and the company is evaluating compensation options for affected users.

A critical security vulnerability in the cross-chain bridge connecting the XRP Ledger (XRPL) and the tx network was exploited on August 9, resulting in the theft of approximately 200,000 XRP (roughly $200,000), according to a statement from the tx team.
The attacker manipulated a flaw in the bridge's deposit detection mechanism, causing the system to record transactions as successful deposits even though no XRP had actually been delivered to the bridge address on the XRPL. This allowed the attacker to mint unbacked bridged XRP on the tx chain and then use those fabricated balances to withdraw real XRP from the bridge's reserve.
In its statement, the tx team explained: "The bridge software incorrectly recorded transactions as investments that didn't actually deliver any $XRP to the bridge, and minted bridged $XRP on the tx chain in return. The attacker then used these unbacked balances to withdraw real $XRP from the reserve."
The company noted that the bridge had undergone multiple internal and third-party security audits prior to launch, but the vulnerability went undetected during those reviews. The failure of pre-launch audits to catch the deposit-detection flaw underscores a broader challenge in cross-chain bridge security, where even reviewed code has repeatedly proven vulnerable to novel exploit vectors. Bridge protocols have consistently ranked among the most targeted categories of DeFi infrastructure, with several high-profile incidents involving audited systems in recent years.
According to tx, the impact of the attack was confined to bridged XRP on the tx chain. All bridged XRP currently in circulation is no longer backed one-to-one with actual XRP reserves. Other bridged assets were reported to be fully secured, and the team emphasized that tokens and user funds held on centralized exchanges, decentralized exchanges, or directly on the blockchain were unaffected.
Upon detecting the incident, the tx team shut down the XRPL-tx bridge. The security vulnerability has since been identified, and corrective measures have been applied to the relevant code.
The team is actively tracking the movement of stolen funds across multiple blockchain networks and collaborating with blockchain forensics firms. A formal complaint has also been filed with the FBI Internet Crime Complaint Center (IC3), including all transaction records related to the attack and any additional information that could assist in identifying the attacker.
tx management stated that it is evaluating various options for compensating affected users. Details regarding the compensation mechanism and an implementation timeline will be announced in a future update. The company also confirmed that all available legal avenues will be pursued to identify and prosecute the attacker.
The XRPL-tx bridge will remain suspended until security reviews and system upgrades are fully completed.
Source: CryptoNews.net