Nearly 200,000 XRP drained from Coreum's XRPL bridge after relayers mistook attacker self-payments for deposits.
199,916.3 XRP drained from Coreum's XRPL bridge on Aug. 9 after relayers treated attacker self-payments as deposits, on-chain analysis shows.
The report from XRPL.to, published Aug. 11, traced the outflow through 94 payments over 97 minutes, each carrying the bridge's own multisignature authorization with 17 signatures from its 28 relayer keys. The evidence does not indicate those keys were stolen.
The bridge held about 200,410 XRP before the sequence began at 19:16 UTC; by 20:53 UTC its balance had fallen to 493.5 XRP. XRPL.to found 21 relayers attested the attacker's first phantom transaction.
The incident centers on software connecting two independent networks rather than an XRP Ledger consensus failure, and Coreum had not published an official incident report by Tuesday while the bridge remained halted.
Relayers mistook self-payments for deposits
The attack targeted how Coreum's relayers interpreted transactions. The attacker first moved the bridge's own wrapped Coreum token between wallets under their control while attaching a memo formatted for the bridge. Those transactions appeared in the bridge account's history because the account issues the wrapped token.
The public relayer code checks whether a payment succeeded, extracts a Coreum recipient from its memo and reads the delivered amount before submitting deposit evidence. The published processing flow does not compare the payment's destination with the bridge address, allowing wallet-to-wallet transfers carrying the right memo to be interpreted as deposits.
Once enough matching evidence reached the Coreum contract, the system credited balances not backed by real deposits. The attacker then used the bridge's normal withdrawal process, prompting its relayers to authorize real XRP payments. The pattern echoes a wider bridge security problem: cross-chain systems can fail even when their underlying blockchains remain secure if the mechanism verifying events on another chain accepts incorrect information.
XRP Ledger data contradicts the rippling theory
An initial warning blamed "rippling" and the bridge account's DefaultRipple setting. The later transaction analysis rejected that explanation. XRP Ledger documentation states that rippling applies to issued assets held through trust lines, and native XRP does not use those trust lines.
XRPL.to attributed all 199,916.3 XRP removed from the account to payments signed by the bridge itself and found no XRP leaving through a rippling route. It also found the transactions were not partial payments, so the incident does not currently point to an XRP Ledger consensus failure.
The two initial receiving wallets forwarded nearly all the XRP within hours. XRPL.to traced roughly 169,000 XRP into two staging accounts created on June 28, with another roughly 34,000 XRP moving toward three other wallets. The analysis has not identified the attacker.
No further XRP left the bridge after 20:53 UTC on Aug. 9. Its account made one additional wrapped token transaction early the next morning before going silent, while the bridge contract was subsequently reported halted. The bridge's own specification allows any relayer or the contract owner to halt operations when unexpected behavior occurs, while only the owner can resume them.
The team behind the bridge has a history of rebranding: it created Sologenic (SOLO) on the XRPL, launched its own Layer 1 blockchain Coreum, and in March 2026 merged both ecosystems under the U.S. brand TX focused on tokenizing real-world assets. That a company claiming institutional status made such a basic error in its cross-chain verification logic damages TX's reputation more than the amount lost, shifting the question from a random bug to systemic quality control.
The next steps to watch are a formal incident report, remediation of the destination verification flaw, any recovery efforts involving the transferred XRP and a decision on when the bridge can safely reopen. XRP traded at $1.01, down 3.2 percent over 24 hours, as the exploit added to selling pressure across the token.
This article is for informational purposes only and does not constitute investment advice.