XRP Bridge Hacked for Nearly $202,000 in XRP
A vulnerability in an XRP bridge allowed an attacker to drain nearly 200,000 XRP from its reserves on August 9.
The attack exploited a software flaw that incorrectly treated transactions as legitimate deposits. The attacker created unbacked balances on the Tx Chain, which were then exchanged for real XRP held in the bridge's reserves.
Tx, the ecosystem operating the bridge, said its deposit-detection software was at fault, not the underlying XRP Ledger itself. Multiple internal and third-party audits had failed to detect the vulnerability before the bridge went live.
The attacker exploited the flaw by creating transactions that appeared to satisfy the bridge's deposit conditions. The software then credited the attacker with XRP on the Tx Chain without corresponding XRP being locked in the bridge's reserves.