XRP bridge drained: $200,000 lost in 97 minutes via relay code flaw

Share

A cross-chain bridge connecting the XRP Ledger to the tx network (formerly Coreum) was drained of nearly $200,000 in XRP in just 97 minutes on August 9, 2026. The attacker exploited a flaw in the relay code that mistook fake deposits for legitimate transactions, reigniting the debate over the security of crypto bridges.

🔑 Key takeaways

  • Approximately 200,000 XRP (≈$200,000) stolen in 97 minutes from the XRPL–tx bridge
  • Flaw: relays approved payments carrying the bridge memo without verifying the destination address
  • tx halted the bridge, patched the code, and filed a complaint with the FBI’s IC3
  • XRP fell below $1 on August 11, 2026, the first time since January 2024
  • Derivatives: funding rates +211%, open interest +7.6% to $2.52B

How a bridge’s validation logic was betrayed

A cross-chain bridge typically operates on a deposit-receipt model. A user sends XRP to a reserve wallet on the XRP Ledger; the bridge then mints an equivalent amount of wrapped XRP on the destination chain (here, tx). To move back, the user burns the wrapped tokens, and the relay releases the real XRP held in reserve.

In this attack, the relay code accepted transactions that had never delivered XRP to the reserve. According to tx, the relay processed payments containing the bridge memo without first verifying the destination address. The attacker was thus able to mint unsupported XRP on the tx blockchain and exchange them for real XRP held in the bridge’s reserve.

Timeline of a 97-minute heist

The drain began at 19:16 UTC on August 9, 2026. Each fraudulent transaction was approved by 17 of the bridge’s 28 relays, meeting the required signature threshold. Relays are programs that monitor both blockchains simultaneously and release withdrawals whenever their internal ledger shows a withdrawal is due. The bridge confirmed to them that the deposits were real, because its own records had already recorded the fraudulent payments as valid deposits.

ParameterValue
Attack startAugust 9, 2026, 19:16 UTC
Total drain duration97 minutes
Tokens stolen≈ 200,000 XRP
Estimated value≈ $200,000
Relays that signed17 of 28
Destination chaintx (formerly Coreum)

tx’s response: halt, patch, and file a complaint

tx suspended the bridge immediately after detecting the attack. The official update posted on X on August 11, 2026, reads: « On August 9, the tx XRPL bridge was exploited and XRP was drained from the bridge’s reserve wallet on the XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. »

The team engaged blockchain forensic specialists to trace the funds and filed a complaint with the FBI’s Internet Crime Complaint Center (IC3). The vulnerable code was identified and patched. However, tx has not yet clarified how affected holders will be compensated, a sensitive question given that the stolen XRP was quickly dispersed across multiple other addresses according to on-chain tracking.

« The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. »

tx official statement, August 11, 2026

Market impact on XRP

The incident amplified bearish pressure on XRP. On August 11, 2026, the token slipped below the symbolic $1 threshold for the first time since January 2024, according to Pluang. The drop extends a broader downtrend: XRP had already shed 6% during the first two days of February 2026 and was trading at $1.57 at the time of writing per a Yellow source.

Derivatives indicators signal intense activity. Funding rates surged 211% and open interest rose 7.6% to $2.52 billion. The RSI (Relative Strength Index) plunged to 25, a deeply oversold level, before bouncing back to 35 — reflecting a technical rebound of XRP against Bitcoin after five consecutive down sessions.

IndicatorChangeReading
XRP price< $1 (August 11, 2026)Lowest since January 2024
Funding rates+211%Bullish speculative positioning
Open interest+7.6% to $2.52BHeightened trader interest
RSI25 → 35Oversold to technical rebound

The tx bridge incident adds to a long list of exploits that have hit crypto bridges. These protocols often hold hundreds of millions of dollars in reserves while relying on smart contracts and validation software that are notoriously difficult to audit thoroughly. The bug here was not cryptographic but logical: an insufficient check on the destination address, a class of error that rigorous integration testing could have caught.

For users, this is a reminder that a wrapped token is a claim on the bridge’s reserve, not native XRP. Until audit standards, bug bounty programs, and relay diversification are standardized across the industry, every new bridge remains a prime target for attackers.


Conclusion: security before growth

The tx bridge attack once again shows that cross-chain liquidity remains an experimental field. The speed of the drain — 97 minutes — and the fake consensus of 17 relays highlight how quickly a validation flaw can be exploited at scale. Bullish scenario: if tx fully compensates users and publishes a complete audit, confidence could return and XRP could erase the $1 breakdown. Bearish scenario: in the absence of clear guarantees, the incident fuels distrust and weighs on the token’s valuation in the medium term. Either way, the episode confirms that software security remains the main bottleneck of blockchain interoperability.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles