XRP bridge loses 200,000 XRP after relayer logic flaw

0
24

Coreum XRPL Bridge Exploit Drains Nearly 200,000 XRP

A security incident involving the Coreum XRPL Bridge resulted in the loss of nearly 200,000 XRP on August 9 after an attacker reportedly exploited a flaw in the bridge’s relayer logic. Available evidence indicates that the issue was related to the bridge’s software design rather than any vulnerability within the XRP Ledger (XRPL) itself.

Nearly 200,000 XRP Withdrawn in Under Two Hours

Blockchain analysis shows that approximately 199,916 XRP was withdrawn from the bridge account through 94 transactions over a period of about 97 minutes.

Before the attack began, the bridge held roughly 200,410 XRP. By the end of the incident, its balance had fallen to just under 500 XRP. Each withdrawal was approved through the bridge’s normal multisignature process, receiving the required number of relayer signatures. Investigators have found no evidence that the relayer keys themselves were compromised.

Relayer Logic Appears to Be the Root Cause

Researchers believe the attacker exploited how the bridge interpreted transactions rather than breaking cryptographic security.

The attacker reportedly transferred wrapped Coreum tokens between wallets they controlled while attaching bridge-formatted memos. Because of a flaw in the relayer process, these transactions were mistakenly recognized as legitimate deposits.

Analysis of the publicly available relayer code suggests that the system validated successful payments and extracted memo information but failed to verify that the transaction destination matched the bridge’s address. As a result, certain wallet-to-wallet transfers were treated as valid deposits even though no real assets had been deposited into the bridge.

Once the bridge credited those phantom deposits, the attacker was able to request withdrawals and receive real XRP from the bridge account.

XRP Ledger Itself Was Not Exploited

Early speculation suggested the incident might be related to XRPL’s “rippling” feature. However, subsequent analysis rejected that theory.

According to XRP Ledger documentation, rippling only applies to issued assets that operate through trust lines. Native XRP does not use trust lines, making that explanation inconsistent with the transaction data.

Investigators found that all of the stolen XRP was transferred through payments signed by the bridge itself, with no evidence of unauthorized XRP movement through rippling mechanisms or XRP Ledger consensus failures.

This distinction is important because it indicates the problem originated in the bridge infrastructure rather than the XRP Ledger network.

Stolen Funds Moved Through Multiple Wallets

After receiving the XRP, the attacker quickly distributed the funds across several wallets. Analysts traced approximately 169,000 XRP into two staging addresses, while additional amounts were sent to several other wallets.

The identities of those controlling the addresses remain unknown.

Following the exploit, the bridge was reportedly halted, and no additional XRP withdrawals have been observed since the attack ended. Coreum had not released a detailed public incident report at the time of the analysis.

What Happens Next?

The focus now shifts to Coreum’s investigation and recovery efforts. Key issues include identifying the attacker, addressing the destination-verification flaw, evaluating whether any funds can be recovered, and determining when the bridge can safely resume operations.

At present, the evidence suggests this was a bridge-level security failure rather than a weakness in the XRP Ledger itself.