Two days after the incident, it emerged that the Coreum cross-chain bridge lost approximately 200,000 XRP during a 97-minute attack. The TX team, formerly known as Sologenic and Coreum, was targeted using wrapped tokens that they themselves had issued. The relayer operators only checked transfer details without verifying the recipient address, allowing the attacker to spoof transactions. Each malicious payment was signed with the bridge’s legitimate multisignature configuration, with 17 out of 28 validators approving. At the time of writing, the TX team had still not released an official post-mortem report, and the Coreum bridge remains suspended.
Source: Read the original article

