An attacker drained nearly 200,000 XRP worth approximately $202,000 from a bridge connecting the XRP Ledger and Tx Chain after exploiting a flaw that caused the bridge to recognize transactions as legitimate XRP deposits even though no XRP had actually been transferred. The vulnerability allowed the attacker to generate unbacked bridged XRP on Tx Chain and then exchange those artificially created balances through the bridge for real XRP held in its reserves.
The August 9 attack is particularly concerning because Tx says the bridge underwent multiple internal and third-party security audits before deployment, yet the vulnerability remained undetected. The bridge has since been shut down while developers review its security, and Tx says it is evaluating options for compensating affected users.
Bridge Software Mistook Fake Deposits for Real XRP
The vulnerability was located in the bridge’s deposit-detection logic.
When users legitimately move XRP through the bridge, its software is supposed to verify that XRP has actually been delivered before creating the corresponding bridged assets on Tx Chain.
The attacker discovered a way to make the software register transactions as deposits without actually sending XRP to the bridge.
Those fake deposits caused the system to mint bridged XRP that had nothing backing it. The attacker could then send the unbacked assets back through the bridge and withdraw real XRP from its reserves.
Nearly 200,000 XRP Drained in 97 Minutes
Independent XRP Ledger analytics platform XRPL analyzed the transactions and determined that approximately 199,916 XRP left the bridge.
The funds were distributed through 94 payments over approximately 97 minutes.
Each payment was authorized by 17 of the bridge’s 28 relayers. Relayers are programs responsible for monitoring activity across the two blockchains and approving transfers through the bridge.
The problem was that the relayers incorrectly interpreted the attacker’s self-directed transactions as legitimate XRP deposits.
Once those transactions were accepted, the attacker’s artificially created balances could be withdrawn using the bridge’s normal transfer process.
Initial Reports Incorrectly Blamed XRP’s Rippling Feature
Early reports suggested the exploit might have involved rippling, a feature of the XRP Ledger that allows issued tokens to move through interconnected trust lines.
Further blockchain analysis found that explanation was incorrect.
Native XRP cannot be transferred through rippling, and XRPL’s analysis found that every payment involved in the attack had actually been approved by the bridge’s own multisignature system.
The evidence instead pointed directly toward the bridge’s relayers mistakenly treating the attacker’s own transactions as deposits.
That distinction is important because the incident was not an exploit of the XRP Ledger itself. The vulnerability existed in the third-party bridge infrastructure connecting XRP Ledger with Tx Chain.
Stolen XRP Was Converted to Ethereum
After obtaining the XRP, the attacker quickly began moving the stolen assets.
According to Reza Bashash, a principal at CoreNest Capital and co-founder of Sologenic and Coreum, the attacker converted the stolen XRP into Ethereum.
The funds were then transferred onto Ethereum through THORChain before ultimately being sent to crypto mixer Tornado Cash.
Moving the funds through several networks and eventually into a mixer makes tracing and potentially recovering the stolen assets considerably more difficult.
Tx Chain Was Created From Coreum and Sologenic
Tx is a Layer 1 blockchain ecosystem launched in March following the combination of Coreum and Sologenic.
Sologenic was built around tokenization and trading infrastructure connected to the XRP Ledger, while Coreum developed its own Layer 1 blockchain.
The exploited bridge provided connectivity between Tx Chain and XRP Ledger, allowing assets to move between the two ecosystems.
The vulnerability therefore affected the bridge infrastructure rather than XRP Ledger’s underlying consensus or native XRP functionality.
Multiple Security Audits Failed to Find the Bug
One of the biggest questions raised by the attack involves how the vulnerability survived multiple security reviews.
According to Tx, the bridge underwent several internal and third-party audits before deployment.
None identified the flaw in its deposit-detection logic.
The incident demonstrates one of the persistent challenges surrounding blockchain bridges. Even when the underlying networks remain secure, bridges must accurately interpret transactions occurring across multiple blockchains.
A relatively small mistake in that verification process can allow attackers to create assets on one network without providing the collateral those assets are supposed to represent on another.
Tx Shuts Down Bridge and Contacts FBI
Tx responded by immediately halting the bridge.
The project says it has:
- Fixed the affected code.
- Traced the stolen funds.
- Hired blockchain forensic specialists.
- Contacted security partners.
- Filed a complaint with the FBI’s Internet Crime Complaint Center.
- Begun evaluating options for compensating affected users.
The bridge remains offline while Tx conducts a broader security review.
The project says holders do not currently need to take action and warned users against websites or social media accounts claiming they can recover funds connected to the exploit.
XRP Price Barely Reacts to the Attack
Despite the bridge exploit, the broader XRP market showed relatively little reaction.
At the time of Decrypt’s August 12 report, XRP remained around $1.01 with a market capitalization near $64 billion. The cryptocurrency was down roughly 5.5% over the previous 30 days, but there was no indication that the bridge incident itself had produced a major market selloff.
The limited reaction likely reflects the fact that the vulnerability involved a specific third-party bridge rather than XRP Ledger’s underlying blockchain.
- Coinbase CEO Apologizes for Delayed Solana Transactions
- Vanguard Prepares to Offer Crypto ETFs to Its Clients On Its Brokerage Platform
- Floki Inu Leads the Pack as Meme Coins Ride the Roaring Kitty Rally
- Newly Launched ‘Hawk Tuah’ Girl Memecoin $HAWK Crashes From Nearly $500M to $60M Market Cap in 20 Mins
- Afroman’s Crypto Token Surges 4,685% After Defamation Trial Victory
- Bitcoin Slips Below $71K as Trump Orders Strait of Hormuz Blockade, Shaking Global Markets




















































































































































