Key facts
- An XRP bridge was drained of nearly 200,000 XRP, valued at approximately $202,000.
- The exploit occurred due to a software flaw that incorrectly registered fake transactions as XRP deposits.
- An attacker minted unbacked bridged XRP and used it to withdraw genuine XRP from the bridge's reserve.
- The bridge connected the XRP Ledger to the tx blockchain.
- Tx has halted the bridge, patched the vulnerability, and filed a complaint with the FBI.
An XRP bridge connecting the XRP Ledger to the tx blockchain was drained of nearly 200,000 XRP, valued at approximately $202,000, due to a software vulnerability. The flaw allowed an attacker to register fake deposits, which then enabled the issuance of unbacked bridged XRP. This unbacked XRP was subsequently used to withdraw genuine XRP from the bridge's reserve wallet.
The incident occurred on August 9, with the drain taking place over 97 minutes. The bridge's software incorrectly recognized transactions as valid deposits even when no XRP was delivered to the reserve. Each withdrawal was authorized by a majority of the bridge's 28 relayers, as the system's records indicated the deposits were legitimate.
Tx has since halted the bridge, identified and fixed the vulnerable code, and engaged blockchain forensics experts. The company has also filed a complaint with the FBI's Internet Crime Complaint Center. Onchain tracking indicates that the stolen XRP was converted to Ethereum, moved to the Ethereum network via THORChain, and sent to the crypto mixer Tornado Cash.
Tx is evaluating potential remedies for affected users, and the bridge remains offline while security is reviewed.
