Full story
Bridge drained in 97 minutes
On August 9, an attacker drained close to 200,000 XRP from a bridge connecting the XRP Ledger and Coreum (now rebranded as tx) after tricking the bridge’s deposit-checking system into treating a wallet-to-wallet transfer as a real deposit.
“lost close to 200,000 XRP after an attacker tricked its deposit-checking system”
CryptoPotato said the bridge “lost close to 200,000 XRP” and that the bridge has since halted, with operator and outside researchers tracing the failure to Coreum-side software rather than anything on the XRP Ledger itself.

BitKE reported the Coreum XRPL bridge lost nearly 200,000 XRP in 94 transactions over about 97 minutes, with the bridge holding roughly 200,410 XRP before the attack and falling to about 493.5 XRP.
The mechanism described across outlets was that the attacker transferred the bridge’s own token between wallets while attaching information that made the transactions appear to be deposits, and the bridge software incorrectly interpreted those transactions as legitimate incoming XRP.
CoinDesk framed the same sequence as a software flaw that let the bridge register non-existent deposits as real, then withdraw real tokens held in reserve, with the drain beginning at 19:16 UTC and the bridge halted afterward.
Competing explanations and quotes
A first public warning came from a trader posting as playa, who flagged that the bridge’s XRPL account rxXXXeMX8Gy5YvibvGLnQJ1XKKD7UswM1 was bleeding funds and pointed to the account’s DefaultRipple setting as the cause.
CryptoPotato quoted playa saying, “I was rushing when I posted and didn’t dig in properly,” after an earlier thread discussion that included Vet writing, “the reason is the coreum bridge was being actively exploited.”

tx later confirmed the exploit in a statement, saying its software “incorrectly registered transactions that never actually delivered any XRP to the bridge.”
DigitalToday’s account added that speculation on social media about the XRP Ledger’s “Rippling” function spread after the incident, but an investigation by xrpl.to found the real cause lay in the bridge’s deposit verification process.
DigitalToday also described the bridge’s relayer approval threshold as 17 signatures collected from 28 relayer keys, and said the attacker did not steal those keys while targeting how relayers verified whether funds reached the bridge’s deposit address.
Aftermath: halted bridge and filings
After the exploit, the bridge remained halted while tx said it had identified and corrected the vulnerable code, engaged blockchain forensics specialists, and filed a complaint with the FBI’s Internet Crime Complaint Center.
“has not disclosed how affected holders will be compensated”
CoinDesk reported that tx “has not disclosed how affected holders will be compensated,” even as it said the vulnerability was identified and all potential remedies were being evaluated.
CryptoPotato said no other bridged assets were affected and that a plan for compensating users is still being worked out, while also stating that the bridge remains halted and a report has been filed with the FBI’s Internet Crime Complaint Center.
The incident also fed into market pressure narratives, with CryptoPotato saying the exploit landed while XRP was already sliding, with the token sitting near $1.02, close to a 21-month low, down roughly 4.4% this week as Bitcoin fell to about $64,000.
BitKE added that XRP briefly fell below $1 on August 11, 2026, its first move below that level since late 2024, and said the bridge exploit added to negative sentiment even though it did not indicate that XRP itself was compromised.


