#XRP Bridge Risk
Software Flaw Drains $200K From XRP Bridge
WooFun2026-08-12 12:54
Key Takeaways
A critical logic error in the tx XRP bridge allowed attackers to withdraw $200,000 in real assets against fake deposits. The exploit triggered an immediate halt and an FBI complaint after relayers approved unbacked transfers.
Woofun AI reports that a software vulnerability in the XRP bridge connecting the XRP Ledger to Coreum, which rebranded as tx this March, resulted in the loss of nearly 200,000 XRP. The incident exposed a fundamental flaw where the system issued bridged tokens without corresponding collateral, effectively draining the reserve wallet.
The financial impact materialized rapidly on Aug. 9, beginning at 19:16 UTC. Within a span of just 97 minutes, the attacker successfully withdrew approximately $200,000 worth of XRP before the system was halted. This swift extraction underscores the severity of the exploit, which bypassed standard security checks to liquidate the bridge's holdings.
Structurally, the exploit relied on a failure in transaction verification rather than a breach of consensus. The attacker manipulated the system by sending transactions with the correct bridge memo but without delivering XRP to the destination address. Consequently, the software registered these empty transactions as valid deposits, creating unbacked bridged XRP on the tx chain.
Notably, the withdrawal process appeared legitimate to the network's validators. Each payout was authorized by 17 of the 28 relayers, a majority that signed off because the bridge's internal records indicated the deposits were real. The relayer code processed payments based on the memo alone, failing to verify the actual destination address or the presence of funds in the reserve wallet.
Per Woofun AI, the project has since identified the vulnerable code, engaged blockchain forensics specialists, and filed a complaint with the FBI's Internet Crime Complaint Center. Onchain tracking reveals that the stolen XRP did not remain static but moved through several other addresses within hours. This marks a significant security failure for the asset tokenization platform.
Comments
No comments yet.