TLDR
- TX Chain reported 198,715.88 XRP stolen from its XRPL bridge during the August 9 exploit.
- A deposit-detection flaw allowed transactions sent elsewhere to register as valid bridge deposits.
- The attacker minted unbacked XRP on TX Chain before withdrawing real XRP from the bridge reserve.
- The stolen XRP was converted to ETH, moved through THORChain and later transferred to Tornado Cash.
- TX Chain halted the XRPL bridge, fixed the vulnerable code and filed a complaint with the FBI.
The cross-chain bridge connecting the TX Chain protocol to the XRP Ledger (XRPL) remains frozen following a targeted smart contract logic vulnerability that drained roughly 198,715 XRP from its liquidity pool. The security breach, which occurred on August 9, was triggered by a critical defect in the bridge relayer software’s deposit-detection mechanism.
This allowed the malicious actor to mint unbacked tokens out of thin air. While the core XRP Ledger protocol itself remains entirely uncompromised and fully secure, the underlying vulnerability in this third-party decentralized application (dApp) highlights ongoing security challenges in cross-chain interoperability.
How the Cross-Chain Exploit Triggered Unbacked XRP Minting
According to a
technical post-mortem by TX Chain developers, the root cause traces back to how the bridge’s off-chain relayer nodes verified incoming transaction data. The attacker manipulated the XRPL’s native DefaultRipple feature to execute cross-currency payments destined for unrelated wallet addresses.
Because the relayer software lacked sufficient destination address validation checks, it misread these external transactions as valid incoming deposits to the bridge vault reserves. This validation breakdown authorized the automated minting of wrapped XRP on the native TX Chain network.
The attacker then used these unbacked assets to systematically drain 198,715.88 real XRP directly out of the bridge’s reserve custody wallets via 94 transactions over a 97-minute window.
Crucially, the hacker did not compromise or steal any private cryptographic keys. Instead, the flawed deposit-detection script fed false verification data to the relayers, tricking the 17-of-28 multi-signature (multisig) configuration into signing off on fraudulent withdrawal requests.
On-Chain Laundering: THORChain to Tornado Cash
Following the drainage, the hacker initiated asset laundering protocols. On-chain data confirms the stolen XRP tokens were rapidly swapped into native Ethereum (ETH), bridged over to the Ethereum Mainnet utilizing the decentralized liquidity protocol THORChain, and routed directly into the
privacy mixer Tornado Cash.
In response, TX Chain mobilized blockchain forensics specialists to map out the transaction history and submitted a comprehensive digital evidence package to the FBI’s Internet Crime Complaint Center (IC3).
While developers have successfully patched the vulnerable validation code, the bridge infrastructure remains suspended pending a third-party smart contract audit.
Addressing the Liquidity Deficit
The
exploit has triggered a localized liquidity crisis for bridged XRP tokens on TX Chain, which are currently under-collateralized.
However, the project team confirmed that all other bridged asset pools remain fully backed 1:1, and user funds held directly on-chain, within centralized trading platforms (CEXs), or via independent decentralized exchanges (DEXs) are completely safe.
Leadership is actively reviewing financial options to restore the asset backing and make affected wrapped XRP holders whole. The XRPL-to-TX Chain bridge will remain offline indefinitely until supplementary protocol safeguards are fully implemented.