An attacker drained nearly 200,000 XRP, worth around $202,000, from the Tx XRPL bridge on August 9 by exploiting a flaw in the deposit-detection software. The software bug caused the bridge to record transactions as XRP deposits even though no XRP had been received, allowing the attacker to create unbacked XRP on Tx Chain and exchange it for real XRP. The attack unfolded in 94 payments over 97 minutes, each authorized by 17 of the bridge’s 28 relayers. Tx halted the bridge, fixed the affected code, and filed a complaint with the FBI’s Internet Crime Complaint Center. The attacker converted the stolen funds to Ethereum through THORChain before sending them to the crypto mixer Tornado Cash, making the funds significantly harder to trace.
Source: Read the original article

