XRP Bridge Drained by Relayer Logic Flaw
Nearly 200,000 XRP was drained from the Coreum XRPL bridge on August 9 after an attacker exploited a flaw in its relayer logic.
The attack, which lasted for 97 minutes, involved 94 signed payments that left the bridge with only 493.5 XRP remaining.
An analysis of the transaction record found that 17 out of 28 relayer signatures authorized each XRP payout from the bridge, but the attacker's success was due to a flaw in how the relayers processed transactions.
The problem arose because the relayer code did not verify the payment destination address before processing successful payments with bridge memos. This allowed the attacker to move the wrapped Coreum token between wallets under their control while attaching a memo formatted for the bridge, which was then interpreted as deposits by the relayers.
The attack does not point to an XRP Ledger consensus failure, but rather a software issue connecting two independent networks. The incident has led to the bridge being halted, and it is unclear when it will reopen.