An attacker drained 199,916 XRP, valued at $202,690, from a bridge connecting the XRP Ledger and the tx blockchain on Aug. 9. The exploit depleted approximately 99.7 percent of the bridge's XRP reserve in 97 minutes, starting at 19:16 UTC.
The attack leveraged a critical software flaw that allowed transactions to register as deposits even when no actual XRP was delivered to the bridge's reserve wallet. That vulnerability generated unbacked bridged XRP on the tx chain, creating fraudulent balances from nothing.
Those fake balances enabled the attacker to initiate withdrawals of real XRP from the bridge's main reserve. The bridge's own relayer network, designed to validate cross-chain transfers, then authorized each payout. Seventeen of 28 relayers signed off—the bridge's internal records, corrupted by the fake deposits, showed the withdrawals as legitimate.
Digital asset bridges hold native tokens on one blockchain while minting wrapped equivalents on another. A user sends XRP to the bridge's reserve wallet on the XRP Ledger and receives corresponding bridged XRP on the tx chain. Returning those wrapped tokens permits withdrawal of the original XRP.
The tx bridge links the XRP Ledger to the Coreum blockchain and is operated by tx, a U.S.-based entity. Coreum rebranded to tx in March, with a stated focus on tokenizing real-world assets. The integrity of its bridge is critical to its ability to move assets across chains for those applications.
The vulnerability resided in the relayer code's processing logic. It processed payments carrying the bridge's memo without first verifying the destination address for actual XRP receipt—bypassing a fundamental security check for inbound funds and making the system susceptible to deposit forgery.
tx confirmed the deposit-detection flaw, saying its software incorrectly recognized zero-value transactions as valid deposits. That flaw reportedly went undetected during multiple security audits of the bridge's code, raising questions about the thoroughness of prior assessments.
After discovering the drain, tx immediately halted the bridge to prevent further losses. The company said it identified and fixed the vulnerable code and has since engaged blockchain forensics specialists to trace the stolen funds and conduct a post-mortem analysis.
tx also filed a formal complaint with the FBI's Internet Crime Complaint Center, initiating a federal investigation into the exploit.
As of publication, tx has not released details on how affected holders of the drained XRP will be compensated, creating uncertainty for users who had funds locked in the bridge at the time of the exploit.
On-chain analysis confirms the stolen XRP did not remain in the attacker's initial wallets. Most of the 199,916 XRP moved through several other addresses within hours of the exploit, complicating efforts to freeze or recover the assets.
