XRP Bridge Drained of $200K After Software Flaw Allows Fake Deposits
A recent software flaw in an XRP bridge led to the unauthorized withdrawal of nearly $200,000 worth of XRP. On August 9, at 19:16 UTC, the bridge connecting the XRP Ledger to the tx blockchain was exploited by an attacker who took advantage of a bug that allowed fake deposits to be registered as real ones.
The bridge's software incorrectly recognized transactions that delivered no XRP to the reserve wallet, issuing unbacked bridged XRP that the attacker then used to withdraw genuine XRP from the reserve wallet. The drain began at 19:16 UTC and lasted for 97 minutes before the system was halted.
The bridge's relayer code processed payments carrying the bridge's memo without first verifying the destination address, allowing the attacker to exploit the software flaw. Tx confirmed the deposit-detection flaw in an update, saying the attacker exploited software that incorrectly recognized transactions that delivered no XRP to the reserve.