On August 9, 2026, an attacker exploited a relayer logic flaw in the Coreum cross-chain bridge, draining 199,916 XRP (valued at nearly the bridge's entire 200,410 XRP balance) in under two hours. The exploit did not compromise the XRP Ledger or private keys; instead, the bridge's relayer code failed to verify transaction destination addresses. This allowed the attacker to spoof deposits using wrapped tokens and trigger 94 legitimate multisig-approved withdrawals. The bridge remains suspended while the stolen funds are being moved through transit wallets.
Story comments
Loading comments…