On August 9, a bridge connecting the XRP Ledger and Coreum (now rebranded as tx) lost close to 200,000 XRP after an attacker tricked its deposit-checking system into treating a wallet-to-wallet transfer as a real deposit.
The bridge has since halted, and both the operator and outside researchers have traced the failure to Coreum-side software rather than anything on the XRP Ledger itself.
What Happened, and How the Alarm Went Out
The first public warning came from a trader posting as playa, who flagged that the bridge’s XRPL account rxXXXeMX8Gy5YvibvGLnQJ1XKKD7UswM1, was bleeding funds and pointed to the account’s DefaultRipple setting as the cause.
Playa said the balance had gone from 93,700 XRP to 77,200 XRP within minutes, a reading taken from an eleven-minute slice of what turned out to be a ninety-seven-minute drain.
Another user, Vet, pushed back in the same thread, writing that “the reason is the coreum bridge was being actively exploited.” Playa later agreed, posting, “I was rushing when I posted and didn’t dig in properly.”
The tx team confirmed the exploit in a statement, saying its software “incorrectly registered transactions that never actually delivered any XRP to the bridge.”
A technical breakdown from Reza Bashash filled in the mechanism: the attacker sent the bridge’s own wrapped token between two of their own wallets, attached a bridge-deposit memo, and because the token is issued by the bridge, the transfer showed up in its history and was read as a genuine deposit.
Relayers approved it, unbacked assets were minted on the Coreum side, and the attacker withdrew real XRP against them. Bashash put the total at 198,715.88 XRP, converted to ETH, routed through THORChain, and ultimately sent to Tornado Cash.
The tx says the vulnerability has been identified, the bridge remains halted, and it has filed a report with the FBI’s Internet Crime Complaint Center. No other bridged assets were affected, and the operator says a plan for compensating users is still being worked out.
A Deeper Look, and a Market Already Under Pressure
A later on-chain review found the same root cause from a different angle: 21 separate Coreum relayers each attested to the same phantom deposit, letting the attacker mint bridge assets with nothing backing them, then repeated the trick with escalating amounts before cashing out.
Every payout that followed on the XRPL Ledger carried a valid multisignature from the bridge’s own relayer quorum, which is why the DefaultRipple explanation didn’t hold up once the transaction data was checked. Native XRP has no trust line to ripple along in the first place, and the flag governs only the bridge’s issued tokens.
The exploit landed while XRP was already sliding. The token sits near $1.02, close to a 21-month low, down roughly 4.4% this week as Bitcoin fell to about $64,000 and the broader crypto market shed some $40 billion in a day.
The post Attacker Drains 200K XRP From Bridge Using Fake Deposit appeared first on CryptoPotato.
Source link