XRP bridge exploit update: tx identifies flaw, alerts FBI

0
14

Tx has confirmed that its XRPL bridge was exploited on Aug. 9, resulting in the theft of nearly 200,000 XRP. The company said the attack was caused by a flaw in the bridge’s deposit verification system, not by a vulnerability in the XRP Ledger itself.

According to Tx technical lead Reza Bashash, attackers stole 198,715.88 XRP by taking advantage of faulty bridge logic. The issue allowed certain transactions that never actually sent XRP to the bridge to be mistakenly recognized as valid deposits.

Because of this error, the bridge created unbacked XRP balances on the Tx network. The attacker then used those balances to withdraw real XRP from the bridge’s reserve wallet.

Tx explained that the main problem was a failure to properly verify transaction destinations. The bridge relayers accepted transactions containing the correct bridge memo but did not fully confirm that the XRP was sent to the bridge’s official vault address.

Once enough relayers approved these fake deposits, the system credited the attacker with XRP that did not exist, allowing them to redeem real funds from the reserve.

The XRPL bridge has been taken offline while developers review additional security improvements and assess recovery options. The company says the vulnerable code has already been fixed, but no date has been announced for reopening the bridge.

Investigators have traced the stolen XRP after it was converted into Ethereum. The funds were reportedly moved through THORChain and later sent to Tornado Cash, a privacy-focused crypto mixing service that makes tracking assets more difficult.

Tx said it has filed a complaint with the FBI’s Internet Crime Complaint Center (IC3) and provided transaction records along with other information that could help identify those responsible.

The company emphasized that the incident only affected bridged XRP. Other assets connected through the bridge remain fully backed. However, bridged XRP currently does not have full reserve backing, and a reimbursement plan has not yet been announced.

For affected users, the project says no action is required at this time. Tx stated that it is working on a recovery plan and will provide further details, including timelines and possible compensation measures, in a future update.

The incident is another reminder of the risks facing cross-chain bridges, which have been a frequent target for hackers and have been responsible for billions of dollars in crypto losses over the past several years.