XRP Bridge Drained After Software Treats Fake Deposits as Real

A flaw that went undetected during multiple audits allowed an attacker to create unbacked balances and withdraw XRP from the bridge’s reserves.

By Jason Nelson

3 min read

An attacker drained nearly 200,000 XRP, worth around $202,000, from an XRP Ledger bridge on August 9 by exploiting a flaw in its deposit-detection software, the project said.

In a post on X on Tuesday, Tx, which operates the bridge connecting the Tx Chain and the XRP Ledger, said a software flaw caused the bridge to record transactions as XRP deposits even though no XRP had been received.

Myriad: XRP price next move? Click the image to place your prediction.

“The attacker exploited the bridge's deposit-detection logic,” the company wrote. “The bridge's software incorrectly registered transactions that never actually delivered any XRP to the bridge as deposits, and minted bridged XRP on the tx chain against them.”

Tx is a layer-1 blockchain ecosystem launched in March by combining the Coreum blockchain with Sologenic, an XRP Ledger-based tokenization and trading platform.

The attacker used those fraudulent deposits to create unbacked XRP on the Tx Chain, then exchanged it through the bridge for real XRP.

According to Tx, the bridge underwent several internal and third-party audits before deployment, but the vulnerability was not identified.

XRPL, an independent XRP Ledger trading and analytics platform, found that the bridge released approximately 199,916 XRP through 94 payments over 97 minutes. Each payment was authorized by 17 of the bridge’s 28 relayers, programs that monitor both blockchains and approve transfers.

According to XRPL, the relayers mistook the attacker’s self-directed transactions for deposits. The attacker then withdrew the resulting unbacked balances through the bridge’s normal process.

The analysis rejected an initial claim that the XRP had been drained through “rippling,” an XRPL feature that moves issued tokens across trust lines. Native XRP cannot move through rippling, according to XRPL.

“A widely-shared warning blamed “rippling” and an on-by-default account flag. The ledger says otherwise: every one of those payments was signed by the bridge’s own multisig, and native XRP cannot be rippled at all,” XRPL wrote. “Reading both public chains together, the real cause is a relayer that mistook the attacker’s own self-payments for deposits.”

In a separate post on X, Reza Bashash, a principal at CoreNest Capital and co-founder of Sologenic and Coreum, said the attacker converted the stolen XRP to Ethereum, moved it onto the Ethereum network through THORChain, and sent the entire amount to crypto mixer Tornado Cash, making the funds significantly harder to trace.

Tx said it halted the bridge, fixed the affected code, traced the stolen funds, and filed a complaint with the FBI’s Internet Crime Complaint Center. It also hired blockchain forensics specialists and is working with security partners.

“As we pursue all legal paths forward, we are simultaneously evaluating all options for remedying the situation for affected users,” tx said.

The bridge remains offline while tx reviews its security. The project said holders do not need to take action and warned against accounts or websites claiming they can recover the funds.

The price of XRP hasn't budged much, despite the issues on the network. The Ripple-linked token continues to hover around the $1 mark, at roughly a $64 billion market cap, dropping roughly 5.5% over the last 30 days.

Traders on Myriad, a prediction market build by Decrypt's parent company, currently believe XRP continues to stay at the $1 price point for the rest of the week.

Get crypto news straight to your inbox--

sign up for the Decrypt Daily below. (It’s free).

Recommended News