XRP Bridge Drained of Nearly 200,000 XRP via Relayer Logic Flaw

1 hour ago 2 sources negative

Key takeaways:

  • The exploit erodes confidence in XRP's DeFi ecosystem, despite the ledger itself remaining uncompromised.
  • Relayer logic flaws highlight systemic bridge risks, urging stricter validation protocols before re-enabling.
  • Lack of swift incident response may prolong negative sentiment, pressuring XRP's short-term market outlook.

Nearly 200,000 XRP was drained from the Coreum XRPL bridge on August 9 after an attacker exploited a critical flaw in the bridge’s relayer logic, on-chain analysis has revealed. The incident did not stem from a vulnerability in the XRP Ledger itself, but from how bridge relayers validated incoming transactions.

The attack unfolded over 97 minutes, during which 94 signed payments removed 199,916.3 XRP from the bridge account. Before the sequence began at 19:16 UTC, the bridge held roughly 200,410 XRP. By 20:53 UTC, its balance had plummeted to just 493.5 XRP. Each outgoing payment carried the bridge’s own multisignature authorization, with 17 of 28 relayer keys signing off on every transfer. Crucially, those keys were not stolen; the relayers were tricked into approving illegitimate withdrawals.

The exploit hinged on a missing destination check in the relayer code. The attacker moved the bridge’s own wrapped Coreum token between wallets while attaching a memo formatted for the bridge. The public relayer code verified that the payment succeeded and extracted a Coreum recipient from the memo, but never confirmed that the payment’s destination was the bridge address. As a result, wallet-to-wallet transfers carrying the correct memo were interpreted as valid deposits. Once enough relayers attested to these phantom transactions, the Coreum contract credited balances that were not backed by real funds. The attacker then used the normal withdrawal process to prompt relayers to authorize genuine XRP payouts.

An initial warning had blamed “rippling” and the bridge account’s DefaultRipple flag, but on-chain evidence disproves that theory. XRP Ledger documentation states that rippling applies only to issued assets held through trust lines, and native XRP does not use trust lines. All removed XRP left through payments signed by the bridge itself; no funds were lost via rippling routes or partial payments. The analysis therefore clears the XRP Ledger of any consensus failure and shifts focus entirely to the bridge’s off-chain logic.

The stolen XRP was quickly forwarded: approximately 169,000 XRP moved to two staging wallets created on June 28, while another 34,000 XRP went to three other addresses. The bridge remained halted after the incident, and Coreum had not published an official incident report by August 11. The bridge’s specification allows any relayer or the contract owner to halt operations, but only the owner can resume. Next steps include a formal post-mortem, remediation of the destination verification flaw, potential recovery efforts, and a decision on when the bridge can safely reopen.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.