TLDR
- Nearly 200,000 XRP worth around $200,000 was drained from a bridge linking the XRP Ledger to the Coreum (tx) blockchain on August 9
- A software flaw let the attacker create fake deposit records without actually sending any XRP to the bridge
- The bridge’s relayers, seeing valid-looking records, signed off on 94 real XRP withdrawals over 97 minutes
- The stolen XRP was moved through multiple wallets within hours of the attack
- The bridge has been halted, the flaw has been fixed, and a complaint has been filed with the FBI
An attacker drained nearly 200,000 XRP from a blockchain bridge on August 9 by exploiting a software flaw that let fake deposits trigger real withdrawals.
An update on the XRPL bridge incident.
On August 9, the tx XRPL bridge was exploited and XRP was drained from the bridge's reserve wallet on the XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. This…
— tx (@txEcosystem) August 11, 2026
The bridge connected the XRP Ledger to Coreum, a blockchain that rebranded this March as tx, which focuses on tokenizing real-world assets.
How the Attack Worked
A bridge works like a vault with a receipt system. A user deposits XRP into a reserve wallet, and the bridge creates an equivalent amount of wrapped tokens on the other chain. Returning those tokens lets the user withdraw the original XRP.
The attacker found a way to get those receipts without making a real deposit.
The relayer software, which watches both blockchains and approves transfers, checked whether a payment succeeded and read the memo attached to it. But it did not check whether the payment was actually sent to the bridge address.
The attacker sent wallet-to-wallet transfers with memos formatted to look like bridge deposits. The relayers read those transactions as legitimate and logged them as real deposits.
Once enough relayers agreed, the system credited balances that had no real XRP backing them. The attacker then used the normal withdrawal process to pull real XRP from the bridge’s reserve.
What the Data Shows
On-chain analysis traced 199,916.3 XRP leaving the bridge account through 94 payments between 19:16 UTC and 20:53 UTC. Before the attack, the bridge held around 200,410 XRP. By the end, only 493.5 XRP remained.
Each outgoing payment carried 17 of 28 relayer signatures, the required majority. There is no evidence the relayer keys were stolen.
Blockchain analysts also ruled out an earlier theory blaming the XRP Ledger’s “rippling” feature. Rippling applies to issued assets held through trust lines. Native XRP does not use trust lines, and all 199,916 XRP left through bridge-signed payments, not through rippling.
This was a flaw in the software connecting two networks, not a failure of either blockchain itself.
After the drain, the stolen XRP moved quickly. Around 169,000 XRP went into two staging wallets created on June 28. Another 34,000 XRP moved to three other addresses. The attacker has not been identified.
tx says it has identified and fixed the vulnerable code, hired blockchain forensics specialists, and filed a report with the FBI’s Internet Crime Complaint Center.
The bridge remains halted. tx has not said how affected users will be compensated or when the bridge will reopen.







