Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
XRP bridge drained after software mistook fake deposits for real ones
00

XRP bridge drained after software mistook fake deposits for real ones

Aug 11, 2026

On August 9, 2026, an attacker drained nearly 200,000 XRP (worth $200,000) from the Coreum cross-chain bridge operated by TX. The exploit succeeded because the bridge's relayer software failed to verify if incoming transactions were actually sent to the bridge's wallet, allowing fake deposits to be credited. TX has suspended the bridge, patched the vulnerability, and contacted the FBI, while the underlying XRP Ledger remains secure.

Coreum bridge exploit mechanics

  • ▪An attacker drained nearly 200,000 XRP, worth approximately $200,000, from the Coreum cross-chain bridge on August 9, 2026
  • ▪The Coreum cross-chain bridge, which connects the XRP Ledger to the Coreum blockchain, was operated by TX, a U.S.-based company focused on tokenizing real-world assets

Relayer software validation flaw

  • ▪The exploit occurred because the bridge's relayer software lacked a check to verify that incoming transactions were actually sent to the bridge's own wallet address
  • ▪The attacker exploited the validation flaw by transferring their own wrapped-CORE tokens between wallets they controlled while attaching a Coreum-recipient memo, which the bridge incorrectly registered as real deposits

Attack execution timeline

  • ▪The attacker initiated the exploit with small probe transfers that doubled in size before executing a steady stream of payouts averaging roughly 1,695 XRP every 50 seconds
  • ▪The exploit began at 19:16 UTC on August 9, 2026, and lasted for 97 minutes, during which the bridge's reserve wallet was drained of 199,916.3 XRP across 94 payments

TX response measures

  • ▪As of August 11, 2026, TX had not yet released an official post-mortem report or explained how affected holders would be compensated
  • ▪TX halted the Coreum bridge, patched the vulnerable relayer code, engaged blockchain forensics specialists, and filed a complaint with the FBI's Internet Crime Complaint Center

XRP Ledger security distinction

  • ▪Every malicious payout was authorized by a valid multi-signature quorum of 17 out of 28 relayer keys, which signed the transactions because the software falsely registered the deposits as real
  • ▪The exploit did not compromise the XRP Ledger's core protocols, consensus mechanisms, or native transaction handling, as the vulnerability was entirely within the bridge's relayer software

3 sources

CoinDesk
Ripple news: XRP bridge drained after software mistook fake deposits for real ones
View source article
U.Today
200,000 XRP Lost in 97 Minutes: Who's to Blame? - U.Today
View source article
BeInCrypto
XRP Price Drops Below $1 After Coreum Bridge Hack. First-Time Since 2024
View source article

Story comments

Loading comments…

Related entities

Xrp

Topics

Blockchain interoperabilityCrypto hacksSmart contract exploits