A cross-chain bridge between Tx Chain and the XRP Ledger was exploited via faulty deposit-recognition logic, enabling attackers to mint unbacked bridged balances and withdraw ~199,916 XRP (~$202k) over 97 minutes. Services are suspended pending audit, with remediation under review. The incident highlights persistent bridge/relay verification risk and can pressure near-term sentiment and liquidity around XRP-linked infrastructure, especially given laundering via THORChain and Tornado Cash.
Impact level
● Medium
Affected assets
XRP/USDT-0.70%
AI Insight · XRP/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A cross-chain bridge linking Tx Chain and the XRP Ledger (XRPL) was exploited after attackers abused a weakness in how deposits were identified, draining nearly 200,000 XRP.
According to CoinDesk, the bridge's system incorrectly treated transactions as completed deposits even though no XRP had actually reached the bridge address. The faulty deposit-recognition logic then credited balances on Tx Chain and minted bridged assets without real backing. The attacker subsequently used the normal withdrawal flow to redeem those unsupported balances into real XRP.
On-chain data indicates the exploit took place on Aug. 9. XRPL, an independent XRPL data and transaction analysis platform, said the bridge released about 199,916 XRP over 97 minutes across 94 payments, valued at roughly $202,000 based on the price cited in the report. XRPL attributed the failure to the bridge's relay program misclassifying the attacker's transactions as deposits. While withdrawals require approval from 17 of 28 relays, that process did not flag the anomalous activity.
XRPL also rejected earlier speculation that the "rippling" feature was responsible, noting native XRP does not move via rippling and that mechanism was not the cause of the incident.
The Tx team has suspended bridge services, said the relevant code has been fixed, and reported that it is tracking fund movements. The team has filed a complaint with the FBI’s Internet Crime Complaint Center and brought in on-chain forensic firms and security partners. Reza Bashash, a partner at CoreNest Capital affiliated with Coreum and Sologenic, said the attacker swapped the stolen XRP into Ethereum via THORChain and then sent the funds to the Tornado Cash mixer, complicating further tracing.
Tx said it is assessing remediation options for affected users. The bridge will remain offline until a security audit is completed. The project team added that holders do not need to take additional steps at this time and warned users to be wary of accounts or websites claiming they can recover funds on their behalf.
Tx is a Layer 1 ecosystem launched in March following the merger of the Coreum blockchain and Sologenic, a tokenization and trading platform built on XRPL. The team said the bridge underwent internal and third-party audits before launch, but this vulnerability was not identified.