XRP Ledger Bridge Hacked for $200,000 in Software Flaw Exploit
A software flaw in the XRP Ledger bridge to blockchain platform Coreum (tx) enabled an attacker to drain nearly $200,000 worth of XRP on August 9. The attacker created fake deposit records without actually sending any XRP to the bridge, convincing relayers that valid deposits had been made.
The software flaw allowed the attacker to get receipts for the fake deposits by sending wallet-to-wallet transfers with memos formatted to look like bridge deposits. Once enough relayers agreed, the system credited balances that had no real XRP backing them, enabling the attacker to withdraw real XRP from the bridge's reserve.
On-chain analysis revealed 199,916.3 XRP leaving the bridge account through 94 payments between 19:16 UTC and 20:53 UTC. The stolen XRP was moved quickly, with around 169,000 XRP going into two staging wallets created on June 28.
The bridge has been halted, and tx has identified and fixed the vulnerable code. A report has been filed with the FBI's Internet Crime Complaint Center, and blockchain forensics specialists have been hired to investigate.