XRP Bridge Hacked for $200,000 Due to Software Flaw Mistaking Fake Deposits

An XRP bridge exploit led to the theft of approximately $200,000 worth of XRP. A software flaw enabled the attacker to register fake deposits as real, withdrawing genuine XRP. The bridge is halted, and its operator tx has filed a complaint with the FBI.

Borsaya Newsroom
|
CoinDesk
|
August 12, 2026 at 04:33 AM
|
4 min read
|
XRP Bridge Hacked for $200,000 Due to Software Flaw Mistaking Fake Deposits

A software vulnerability in the bridge connecting the XRP Ledger (XRPL) to the Coreum blockchain, recently rebranded as tx, led to the theft of approximately $200,000 worth of XRP. The incident, which occurred on August 9, 2026, involved an attacker exploiting a flaw in the bridge's deposit verification system to register non-existent deposits as legitimate. This event has once again highlighted security concerns within the cryptocurrency markets.

The attack unfolded over 97 minutes, starting at 19:16 UTC and concluding at 20:53 UTC on August 9. During this period, 198,715.88 XRP, valued at roughly $200,000, was drained from the bridge's reserve wallet. The core issue stemmed from a flaw in the bridge's relayer code. The attacker transferred the bridge's own wrapped Coreum token (wrapped-CORE) between two of their controlled wallets, attaching memos formatted to appear as legitimate bridge deposits. The bridge mistakenly interpreted these transactions as real XRP deposits, allowing the attacker to mint unbacked bridged XRP on the tx chain.

Subsequently, the attacker used these fake balances to withdraw real XRP from the bridge's reserve on the XRPL. Relayers are designed to monitor both blockchains and approve transfers when the bridge's records indicate a withdrawal is due. However, in this exploit, the relayer code processed payments based on the bridge's memo without adequately verifying the destination address. This indicates that the XRP Ledger itself was not compromised; rather, the vulnerability resided in the bridge's middleware or relayer logic.

Following the incident, tx, the bridge operator, promptly halted the bridge, identified, and patched the vulnerability. The company has also engaged blockchain forensics specialists and filed a complaint with the FBI's Internet Crime Complaint Center (IC3). The stolen XRP was quickly converted into Ethereum (ETH) and routed through platforms like THORChain and Tornado Cash, making it difficult to trace.

Such bridge attacks consistently expose security weaknesses within the broader cryptocurrency ecosystem. Cross-chain bridges in the decentralized finance (DeFi) sector, while facilitating asset transfers between different blockchains, also become attractive targets for cyberattacks. This incident underscores the critical importance of robust verification mechanisms within these systems, demonstrating how even a minor flaw can lead to significant financial losses. In the aftermath of the attack, XRP's price fell below $1 for the first time since November 2024, nearing a 21-month low.

Analysts and market experts emphasize that such events necessitate continuous review and strengthening of security infrastructures for decentralized finance projects. While tx has not yet detailed how affected holders will be compensated, it has stated that it is working on security enhancements and recovery options. This incident highlights the growing importance of more robust and error-free verification mechanisms for blockchain bridges as cross-chain interactions become more prevalent. Industry-wide improvements in security standards are expected to prevent similar attacks in the future.

Share
2

₿ Want to ride this crypto move?

Open an account in minutes. Compare brokers offering crypto and start investing today — zero commission options available.

Comments (0)

0/1000

No comments yet. Be the first to comment!

XRP Bridge Hacked for $200,000 Due to Software Flaw Mistaking Fake Deposits | Borsaya.com