200K XRP Drained from Bridge in Fake Deposit Heist
A vulnerability in the Coreum bridge connecting the XRP Ledger and the rebranded tx platform allowed an attacker to drain around 200,000 XRP on August 9.
The attack occurred when the attacker sent a fake deposit using wrapped tokens issued by the bridge. The software incorrectly registered the transaction as a genuine deposit, allowing the attacker to mint new assets and withdraw real XRP.
A trader known as playa initially raised concerns about the suspicious activity on the XRPL account, but it was later confirmed that the issue lay with the Coreum-side software rather than any problem with the XRP Ledger itself.
The bridge has since been halted, and a plan for compensating affected users is being worked out. The vulnerability has also been reported to the FBI's Internet Crime Complaint Center.