An attacker drained roughly 199,916 XRP from the Coreum cross-chain bridge on August 9, exploiting a flaw in the bridge's deposit verification logic rather than any breach of the XRP Ledger itself. The bridge remains suspended as of August 11, with no official incident report yet released.
The Coreum cross-chain bridge connecting to the XRP Ledger lost approximately 199,916 XRP in under two hours on August 9. The bridge's balance fell from roughly 200,410 XRP to just 493.5 XRP.
No XRPL private keys were compromised, and the ledger itself stayed unaffected. Instead, the attacker exploited a flaw in the bridge's relayer logic that treated fake deposit actions as genuine, triggering real XRP withdrawals from the bridge's wallet on the other side.
How the attacker fooled the relayers
The Coreum bridge used a multisig relayer system, where a group of nodes collectively authorizes transactions between XRPL and Coreum's ecosystem. The relayer logic was supposed to confirm that deposits on one chain were genuine before authorizing withdrawals on another, but the attacker submitted fabricated deposit actions that the system accepted as legitimate.
On-chain analysis showed 94 multisig-authorized payment transactions executed across a 97-minute window, from 19:16 to 20:53 UTC. Authorization required 17 of 28 relayer keys to sign off, meaning the exploit fooled the consensus mechanism into approving nearly a hundred illegitimate transactions in rapid succession.
Bridge suspended, no report yet
As of August 11, the Coreum bridge remained suspended. The Coreum Development Foundation had not yet released an official incident report, leaving the community to piece together events through on-chain data and independent analysis.
The bridge launched on March 20, 2024, with a goal of connecting XRPL to over 110 IBC-compatible chains, positioning itself as a gateway for XRP holders to reach DeFi opportunities across that network.
A third-party failure, not a protocol flaw
The core issue was relayer-based verification rather than on-chain cryptographic proof, a design choice that trades security for simplicity. Bridges relying on relayers to attest what happened on another chain are trusting those relayers, and the logic governing them, to be accurate. When that logic has a bug, the entire security model collapses.
Because no XRPL private keys were compromised and the ledger itself was unaffected, the fallout likely stays contained to the bridge rather than the broader XRP ecosystem. This was a third-party infrastructure failure, not a protocol-level vulnerability.
Source: Crypto Briefing
Trading involves risk.