Attackers Drain 200K XRP from Vulnerable Bridge, Funds Laundered Through Tornado Cash
A significant security breach occurred on August 9 when an attacker exploited a vulnerability in a bridge connecting the XRP Ledger and Coreum, draining nearly 200,000 XRP.
The attacker tricked the deposit-checking system by treating a wallet-to-wallet transfer as a real deposit, sending fake transactions that were then validated by relayers on the Coreum side. The funds were converted to ETH and routed through THORChain before being sent to Tornado Cash.
The bridge has been halted, and an investigation found that the issue was caused by software on the Coreum side rather than any problem with the XRP Ledger itself.
The tx team confirmed that their software incorrectly registered transactions that never actually delivered any XRP to the bridge, allowing the attacker to mint bridge assets with nothing backing them. The team has filed a report with the FBI's Internet Crime Complaint Center and is working on a plan to compensate affected users.