An attacker drained nearly 200,000 XRP, worth around $202,000, from the Tx XRPL bridge.
The bridge credited transactions that did not deliver XRP as deposits.
Tx halted the bridge and is considering how to compensate affected users.
An attacker drained nearly 200,000 XRP, worth around $202,000, from an XRP Ledger bridge on August 9 by exploiting a flaw in its deposit-detection software, the project said.
In a post on X on Tuesday, Tx, which operates the bridge connecting the Tx Chain and the XRP Ledger, said a software flaw caused the bridge to record transactions as XRP deposits even though no XRP had been received.
Myriad: XRP price next move? Click the image to place your prediction.
“The attacker exploited the bridge’s deposit-detection logic,” the company wrote. “The bridge’s software incorrectly registered transactions that never actually delivered any XRP to the bridge as deposits, and minted bridged XRP on the tx chain against them.”
Tx is a layer-1 blockchain ecosystem launched in March by combining the Coreum blockchain with Sologenic, an XRP Ledger-based tokenization and trading platform.
The attacker used those fraudulent deposits to create unbacked XRP on the Tx Chain, then exchanged it through the bridge for real XRP.
According to Tx, the bridge underwent several internal and third-party audits before deployment, but the vulnerability was not identified.
XRPL, an independent XRP Ledger trading and analytics platform, found that the bridge released approximately 199,916 XRP through 94 payments over 97 minutes. Each payment was authorized by 17 of the bridge’s 28 relayers, programs that monitor both blockchains and approve transfers.
According to XRPL, the relayers mistook the attacker’s self-directed transactions for deposits. The attacker then withdrew the resulting unbacked balances through the bridge’s normal process.
The analysis rejected an initial claim that the XRP had been drained through “rippling,” an XRPL feature that moves issued tokens across trust lines. Native XRP cannot move through rippling, according to XRPL.
“A widely-shared warning blamed “rippling” and an on-by-default account flag. The ledger says otherwise: every one of those payments was signed by the bridge’s own multisig, and native XRP cannot be rippled at all,” XRPL wrote. “Reading both public chains together, the real cause is a relayer that mistook the attacker’s own self-payments for deposits.”
In a separate post on X, Reza Bashash, a principal at CoreNest Capital and co-founder of Sologenic and Coreum, said the attacker converted the stolen XRP to Ethereum, moved it onto the Ethereum network through THORChain, and sent the entire amount to crypto mixer Tornado Cash, making the funds significantly harder to trace.
Tx said it halted the bridge, fixed the affected code, traced the stolen funds, and filed a complaint with the FBI’s Internet Crime Complaint Center. It also hired blockchain forensics specialists and is working with security partners.
“As we pursue all legal paths forward, we are simultaneously evaluating all options for remedying the situation for affected users,” tx said.
The bridge remains offline while tx reviews its security. The project said holders do not need to take action and warned against accounts or websites claiming they can recover the funds.
The price of XRP hasn’t budged much, despite the issues on the network. The Ripple-linked token continues to hover around the $1 mark, at roughly a $64 billion market cap, dropping roughly 5.5% over the last 30 days.
Traders on Myriad, a prediction market build by Decrypt‘s parent company, currently believe XRP continues to stay at the $1 price point for the rest of the week.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.
We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.
Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.
Your permission applies to the following domains:
https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.