< Back to all clusters
[TECHNOLOGY] · United States · 16 sources

started · updated

Coreum-XRP bridge exploit drains 200,000 XRP

An attacker exploited a software vulnerability in the Coreum cross-chain bridge, which connects the XRP Ledger to the tx network, draining approximately 199,916 XRP (valued at over $200,000) on August 9. The exploit occurred over a 97-minute window through 94 transactions.

The breach was caused by a flaw in the bridge’s relayer logic. The relayers, which are responsible for verifying deposits, incorrectly identified fraudulent transactions as legitimate deposits because they failed to verify the destination of the payments. This allowed the attacker to create unbacked bridged XRP on the tx chain and subsequently withdraw real XRP from the bridge’s reserve.

The incident did not involve a compromise of the XRP Ledger itself or the theft of private keys. The bridge’s multisignature system was used to authorize the withdrawals, as 17 of the 28 relayers signed off on the transactions based on the faulty data.

Following the attack, the tx team halted bridge operations, applied a software patch to fix the vulnerability, and filed a formal complaint with the FBI. The exploit has contributed to market volatility, with the price of XRP dipping below the $1 mark for the first time since late 2024.

Entities

Aave · Coreum · FBI · KelpDAO · SparkLend · TX · XRP · XRP Ledger · XRPL.io

Sources

about 1 month ago
about 1 month ago