27 min ago2 min readXRP bridge drained for $200,000 after software mistook fake deposits for real ones. (Unsplash)SummaryNearly 200,000 XRP, worth about $200,000, were drained from a bridge linking the XRP Ledger to the tx blockchain after an attacker exploited a software flaw.The bug let the bridge register non-existent deposits as real, issuing unbacked bridged XRP that the attacker then used to withdraw genuine XRP from the reserve wallet.Tx says it has halted the bridge, patched the vulnerability, hired blockchain forensics experts and filed an FBI complaint, but has not yet explained how affected holders will be compensated.An XRP bridge lost nearly 200,000 XRP, worth about $200,000 at current prices, after a software flaw let an attacker claim deposits that were never made, then withdraw real tokens against the fake balances.The bridge connected the XRP Ledger to Coreum, a separate blockchain which rebranded this March as tx, a U.S.-based outfit focused on tokenizing real-world assets. The tokens XRP left the bridge's reserve wallet in 97 minutes on Aug. 9 before the system was halted.A bridge is supposed to work like a vault with a receipt system. A user sends XRP into a reserve wallet on the XRP Ledger, and the bridge creates an equivalent amount of bridged XRP on the other chain. Returning those tokens lets the user withdraw the real XRP held in the reserve.The attacker found a way to make that system issue the receipts without putting anything into the vault.According to tx, the bridge's software registered transactions as deposits even though they never delivered XRP to the bridge. That gave the attacker bridged XRP on the tx chain without the real XRP that was supposed to back it. Those unbacked tokens then went back through the bridge, and the attacker withdrew real XRP from the reserve.How a missing check let an attacker withdraw XRP that was never deposited. (Shaurya Malwa/CoinDesk)The drain began at 19:16 UTC. Each payout was authorized by 17 of the bridge's 28 relayers, a majority signing off exactly as designed, because the bridge's own records told them the deposits were real.Relayers are programs that watch both blockchains and approve transfers when the bridge's records say a withdrawal is owed.The specific failure sat one layer down, however, as the relayer code processed payments carrying the bridge's memo without first verifying the destination address.tx confirmed the deposit-detection flaw in an update, saying the attacker exploited software that incorrectly recognized transactions that delivered no XRP to the reserve.An update on the XRPL bridge incident.On August 9, the tx XRPL bridge was exploited and XRP was drained from the bridge's reserve wallet on the XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. This…— tx (@txEcosystem) August 11, 2026
Ripple news: XRP bridge drained after software mistook fake deposits for real ones
An attacker created unbacked XRP on another blockchain, then exchanged it for real XRP held in reserve. The bridge has been halted and its operator has filed a complaint with the FBI.
The $200k tx XRP bridge drain resulted from software that registered fake deposits as real, enabling attackers to mint unbacked tokens and withdraw reserves. The flaw exposes a bridge weakness: relayers validate signatures but cannot verify deposits actually reach the vault.







