XRP bridge drained for $200,000 after software mistook fake deposits for real ones

A bridge connecting the XRP Ledger to the tx blockchain was exploited for $200,000 due to a software flaw that misidentified fake deposits as legitimate. The attacker successfully drained the reserve wallet by tricking the system into issuing unbacked tokens.
Why it matters
This incident highlights the persistent security vulnerabilities in cross-chain bridge infrastructure, which remains a primary target for decentralized finance exploits.
The bridge connected the XRP Ledger to Coreum, a separate blockchain which rebranded this March as tx, a U.S.-based outfit focused on tokenizing real-world assets. The tokens XRP left the bridge's reserve wallet in 97 minutes on Aug. 9 before the system was halted.
A bridge is supposed to work like a vault with a receipt system. A user sends XRP into a reserve wallet on the XRP Ledger, and the bridge creates an equivalent amount of bridged XRP on the other chain. Returning those tokens lets the user withdraw the real XRP held in the reserve.
The attacker found a way to make that system issue the receipts without putting anything into the vault.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in