Key Points
- Approximately 200,000 XRP, valued at roughly $200,000, was stolen from a bridge connecting XRP Ledger to the Coreum (tx) blockchain on August 9
- The exploit leveraged a critical software vulnerability that allowed fabricated deposit entries without actual XRP transfers to the bridge
- Bridge relayers validated these fraudulent records and authorized 94 legitimate XRP withdrawals spanning 97 minutes
- The pilfered XRP was quickly dispersed across several wallets in the hours following the breach
- Operations have been suspended, the vulnerability patched, and federal authorities notified through an FBI complaint
A sophisticated exploit on August 9 resulted in the theft of approximately 200,000 XRP from a cross-chain bridge, after an attacker discovered and weaponized a software vulnerability that accepted fraudulent deposit records as authentic.
The compromised bridge facilitated transfers between the XRP Ledger and Coreum, a platform rebranded as tx in March 2024 that specializes in real-world asset tokenization.
Anatomy of the Exploit
Blockchain bridges function as digital vaults with a voucher mechanism. Users lock XRP in a reserve address, receiving equivalent wrapped tokens on the destination chain. Users can later redeem these tokens to retrieve their original XRP.
The perpetrator discovered a method to obtain withdrawal vouchers without actually depositing funds.
The relayer infrastructure—responsible for monitoring both blockchains and validating transfers—verified transaction success and parsed attached memo fields. However, it failed to confirm whether payments were actually directed to the authorized bridge address.
The attacker executed peer-to-peer wallet transactions containing memos crafted to mimic legitimate bridge deposits. The relayer software interpreted these transactions as valid and recorded them as authentic deposits.
After securing sufficient relayer consensus, the system issued credits without corresponding XRP collateral. The attacker subsequently initiated standard withdrawal procedures to extract actual XRP from the bridge’s reserves.
On-Chain Evidence
Blockchain forensics revealed 199,916.3 XRP exited the bridge wallet via 94 transactions between 19:16 UTC and 20:53 UTC. The bridge’s pre-attack balance stood at approximately 200,410 XRP. Post-exploit, merely 493.5 XRP remained.
Every outbound transaction bore 17 of 28 possible relayer signatures, meeting the threshold for approval. No indication suggests the relayer private keys were compromised.
Investigators also dismissed an initial hypothesis involving the XRP Ledger’s “rippling” mechanism. Rippling affects issued tokens distributed via trust lines. Native XRP doesn’t utilize trust lines, and the entire 199,916 XRP volume was withdrawn through properly signed bridge transactions, not rippling.
The vulnerability resided in the bridge integration software, not in the underlying blockchain protocols of either network.
Following the drainage, the stolen funds were rapidly redistributed. Approximately 169,000 XRP flowed into two intermediary wallets established on June 28. An additional 34,000 XRP was transferred to three separate addresses. The perpetrator remains unidentified.
tx reports it has located and remediated the flawed code, engaged blockchain security forensics experts, and submitted documentation to the FBI’s Internet Crime Complaint Center.
The bridge continues to be offline. tx has not disclosed compensation plans for impacted users or provided a timeline for service restoration.
The post XRP Bridge Exploited for $200K in Sophisticated Fake Deposit Attack appeared first on Blockonomi.
