Incident case file
Sign in to watchCoreum/tx XRPL Bridge — Fake Deposit Relayer Logic Exploit
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
10 beatsAugust 9, 2026 — The XRPL↔Coreum (tx) bridge was exploited via a deposit verification logic flaw, draining 199,916.3 XRP (~$200,000, ~99.7% of reserves) in 97 minutes across 94 multisig transactions.
Background: Coreum rebranded as 'tx' in March 2026 following its merger with Sologenic. The bridge connected the XRP Ledger to the tx/Coreum chain (Cosmos-based), with a 17-of-28 relayer multisig architecture.
Pre-attack staging: Attacker created two XRPL receiving wallets less than 2 hours before the attack. Two additional routing accounts had been created on June 28, 2026.
19:16 UTC, Aug 9: First fraudulent XRPL withdrawal authorized by the relayer system. The attack mechanism: the attacker performed self-transfers of the bridge's own wrapped tokens between attacker-controlled wallets, attaching valid Coreum-formatted memos to each transaction. The bridge relayer software scanned for payments with valid memos and registered them as legitimate deposits — without verifying that the payment destination was the bridge's own XRPL account, and without verifying actual XRP delivery. Each fake deposit triggered a real XRP withdrawal from the bridge reserve.
19:16–20:53 UTC: 94 multisig-authorized XRP payments drain the bridge reserve. ~107,397 XRP transferred to first attacker wallet; ~92,519 XRP to second. Reserve falls from ~200,410 XRP to 493.5 XRP.
20:53 UTC: Final withdrawal. Bridge effectively emptied.
Post-drain: Bridge halted. tx team identifies the exploit path and applies a fix to the relayer verification logic.
Aug 11: @txEcosystem publishes full official statement (tweet 2087269579190046895): confirms exploit, bridge halt, vulnerability fix, forensics engagement, and FBI IC3 complaint filed with complete transaction records. No attacker addresses disclosed (active law enforcement investigation). Notes that bridged XRP on tx chain is 'not currently fully backed.'
Aug 12: Additional coverage by CryptoBriefing, Cryptonomist, Yahoo Tech. xrpl.to confirms the vulnerability was in the bridge software, not in XRPL itself.
As of Aug 20, 2026: Bridge remains halted. Attacker not identified. Compensation mechanism under evaluation. Forensics and law enforcement coordination ongoing.
Sources and coverage
- Articlex.comhttps://x.com/txEcosystem/status/2087269579190046895
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
- Articlecryptobriefing.comhttps://cryptobriefing.com/coreum-bridge-exploit-xrp-drained/
- Articleshattered.iohttps://shattered.io/coreum-bridge-hack-200k-xrp-2026/
- Articlethecryptobasic.comhttps://thecryptobasic.com/2026/08/11/coreum-xrpl-bridge-suffers-200000-xrp-breach-heres-what-happened/
- Articlelivevolatile.comhttps://www.livevolatile.com/blog/tx-coreum-xrpl-bridge-exploit-relayer-flaw
- Articlenewscord.orghttps://newscord.org/article/attacker-drains-nearly-200000-xrp-from-coreum-bridge-after-fake-deposit-trick--Story_20260812_XRPbridgedrainedfor2de55cfd1
- Articleprimexbt.comhttps://primexbt.com/news/coreum-bridge-exploit-drains-nearly-200000-xrp-in-under-two-hours
- Articleen.cryptonomist.chhttps://en.cryptonomist.ch/2026/08/12/xrp-coreum-bridge-hack
- Articletech.yahoo.comhttps://tech.yahoo.com/cybersecurity/articles/xrp-bridge-drained-software-treats-160052628.html
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)