Coreum-XRPL Bridge Drained of 200k XRP Through Phantom Deposits
A recent security incident on the Coreum-XRPL bridge has highlighted a new type of risk in cross-chain systems. The attacker exploited the bridge's transaction-verification logic, causing nearly 200,000 XRP to be drained from the bridge without stealing validator keys or compromising the XRP Ledger itself.
The attack occurred on August 9, when an attacker manipulated transactions between wallets they controlled and attached a memo format expected by the bridge. Relayers mistook these phantom deposits for real funds and treated them as legitimate deposits, even though no actual transfer of funds had taken place.
This led to the creation of unbacked bridge balances representing roughly 200,001 XRP alongside millions of CORE tokens. The attacker could then withdraw the artificially created balance through the bridge's normal process, leaving the bridge with only 493.5 XRP.
The incident highlights that multisig security can protect custody while leaving the assumptions that determine what should be signed vulnerable. In this case, the relayers' flawed verification logic allowed the attacker to drain funds from the bridge without directly compromising its security.