The Software Error: Fake Deposit Verification
Published 8/12/2026, 12:45:15 PM
An XRP bridge connecting the XRP Ledger (XRPL) to the Coreum network (recently rebranded as "tx") lost approximately 199,916 XRP (valued at roughly $200,000) on August 9, 2026, due to a critical software vulnerability in its off-chain relayer logic [Source: https://cryptobriefing.com/coreum-xrpl-bridge-exploit/]. The exploit was not a flaw in the XRP Ledger protocol itself, but rather a failure in how the bridge verified incoming deposits [Source: https://blockonomi.com/xrp-bridge-exploited-200k-fake-deposit-attack/].
The Software Error: Fake Deposit Verification
The specific error involved the bridge's deposit verification logic. The software incorrectly relied on transaction memo data to confirm deposits rather than validating that the XRP had actually been transferred to the bridge's reserve address [Source: https://www.coindesk.com/tech/2026/08/12/xrp-bridge-drained-software-error/].
The mechanics of the exploit followed a four-step process:
- Fabricated Signals: The attacker performed self-transfers of the bridge's own tokens between their own wallets while attaching fake deposit labels in the transaction remarks [Source: https://www.coindesk.com/tech/2026/08/12/xrp-bridge-drained-software-error/].
- Logic Failure: The bridge's relayer software misidentified these internal movements as legitimate incoming XRP deposits from an external source [Source: https://www.coindesk.com/tech/2026/08/12/xrp-bridge-drained-software-error/].
- Unbacked Minting: Based on these "ghost" deposits, the bridge minted unbacked bridged XRP on the Coreum chain for the attacker [Source: https://www.coindesk.com/tech/2026/08/12/xrp-bridge-drained-software-error/].
- Reserve Draining: The attacker used these unbacked tokens to request legitimate withdrawals, which the relayers approved, draining the real XRP reserves [Source: https://www.coindesk.com/tech/2026/08/12/xrp-bridge-drained-software-error/].
Incident Summary
The attack was highly efficient, nearly emptying the bridge's reserves in under two hours.
| Metric | Detail |
|---|---|
| Date & Duration | August 9, 2026 (97-minute window) [Source: https://crypto.news/xrp-bridge-exploit-update-tx-identifies-flaw-alerts-fbi/] |
| Total Loss | 199,916 XRP (~$200,000 USD) [Source: https://cryptobriefing.com/coreum-xrpl-bridge-exploit/] |
| Number of Transactions | 94 fraudulent withdrawals [Source: https://www.coindesk.com/tech/2026/08/12/xrp-bridge-drained-software-error/] |
| Reserve Impact | Dropped from ~200,410 XRP to 493.5 XRP [Source: https://www.coindesk.com/tech/2026/08/12/xrp-bridge-drained-software-error/] |
Response and Recovery
Following the detection of the exploit, the bridge was immediately halted. The development team has since identified and patched the vulnerability [Source: https://crypto.news/xrp-bridge-exploit-update-tx-identifies-flaw-alerts-fbi/]. A formal complaint has been filed with the FBI's Internet Crime Complaint Center (IC3) to assist in tracking the stolen funds [Source: https://crypto.news/xrp-bridge-exploit-update-tx-identifies-flaw-alerts-fbi/].
While some reports suggest the funds were routed through privacy protocols like Tornado Cash to obscure their trail, these specific movements have not been independently confirmed [Note: not independently confirmed]. As of August 12, 2026, the bridge remains offline, and no official compensation plan for affected users has been finalized.