Coreum-XRPL Bridge Loses $200K XRP in Logic Flaw Exploit
A recent incident involving the Coreum-XRPL bridge has highlighted a critical flaw in its transaction-verification logic, resulting in the loss of nearly 200,000 XRP. According to on-chain analysis published by XRPL.to, the attacker exploited the system without stealing validator keys or compromising the XRP Ledger itself.
The incident occurred on August 9, when an attacker made transactions between wallets they controlled and attached the memo format expected by the bridge. Relayers detected these transactions as legitimate deposits and treated them as such, even though no actual funds had been transferred into the bridge.
The flaw in the system's logic allowed the attacker to create unbacked bridge balances representing over 200,000 XRP. These balances were then withdrawn through the bridge's normal process, with valid signatures from 17 of its 28 relayer keys. This highlights a key issue with cross-chain systems: verifying that a transaction exists is not enough, relayers must also establish that funds reached the correct destination and genuinely created the economic deposit being represented.