XRP bridge exploit update: tx identifies flaw, alerts FBI

摘要:On August 9, Txs XRPL bridge was exploited after an attacker abused faulty deposit verification logic, draining 198,715.88 XRP from the bridge reserve. The bridge remains halted while developers review security upgrades and possible user remedies. Stolen XRP was converted to ETH, moved through THORChain, and sent to Tornado Cash. Tx filed an FBI IC3 complaint with transaction records and identifying information. The flaw was in relayer destination checks, not the XRP Ledger itself; unbacked bridged XRP was minted and redeemed for real XRP. Other bridged assets remain fully backed, but bridged XRP is not. Affected holders need not act yet.

Tx said on Aug. 12 that its XRPL bridge was exploited on Aug. 9 after an attacker abused faulty deposit detection logic, draining XRP from the bridge reserve.

Summary

  • Tx says attackers stole 198,715.88 XRP after exploiting a flaw in bridge deposit verification logic.
  • The XRPL bridge remains halted while developers review security upgrades and possible user remedy options.
  • Attackers converted stolen XRP into ETH before routing funds through THORChain and Tornado Cash afterward.
  • Tx filed an FBI IC3 complaint with transaction records and additional identifying information about attackers.
  • Other bridged assets remain fully backed, while bridged XRP currently lacks complete reserve backing.

Technical lead Reza Bashash put the stolen amount at 198,715.88 XRP. The bridge remains halted while the team evaluates recovery options and strengthens the affected software, according to its latest post.

The company said the flaw caused transactions that never delivered XRP to the bridge to be registered as deposits. This allowed unbacked bridged XRP to be minted on the tx chain. The attacker then withdrew real XRP from the reserve wallet against those balances.

You might also like:

XRP bridge loses 200,000 XRP after relayer logic flaw

Tx says destination checks failed in the bridge relayer

Tx said the vulnerability was in the bridge software rather than the XRP Ledger itself. Bashash described the issue as a bug in XRPL relayer logic involving cross currency payments and the DefaultRipple feature. The central failure, according to both the company and independent ledger analysis, was insufficient destination validation.

An update on the XRPL bridge incident.

On August 9, the tx XRPL bridge was exploited and XRP was drained from the bridge's reserve wallet on the XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. This…

The relayers accepted transactions carrying the expected bridge memo without confirming that the destination was actually the bridge vault. Once enough relayers attested to those false deposits, the tx side bridge logic credited unbacked balances that could be redeemed for genuine XRP.

As previously reported, public ledger analysis traced 199,916.3 XRP leaving the bridge in 94 payments over 97 minutes. That earlier figure measures XRP released from the reserve, while Bashash now says 198,715.88 XRP was stolen. Tx has not publicly explained the roughly 1,200 XRP difference between the figures.

DefaultRipple did not itself drain native XRP

Earlier discussion of the incident focused on DefaultRipple, an XRP Ledger setting that applies to issued assets. XRPL.to‘s analysis found that native XRP did not leave through rippling. Instead, all observed XRP releases were signed by the bridge’s own multisignature setup.

The analysis found 17 of 28 relayer signatures on the bridge payouts and 21 relayers attesting the attackers first phantom deposit. That evidence points to shared verification logic accepting invalid input rather than stolen signing keys.

The distinction matters because tx described the incident as “isolated” to bridged XRP. Other bridged assets remain fully backed, according to the company. Bridged XRP on the tx chain is not currently fully backed, and the team has not yet announced a reimbursement mechanism.

Stolen XRP moved through THORChain and Tornado Cash

Bashash said the stolen XRP was converted into ETH, moved to Ethereum through THORChain and ultimately transferred to Tornado Cash. Direct tracing becomes more difficult after funds enter the privacy protocol, although investigators can still examine the transaction history leading to that point.

The bridge between the TX Chain and XRP Ledger (XRPL) was exploited due to a bug in the XRPL relayer logic combined with the XRPL DefaultRipple feature.

The attacker constructed cross-currency XRPL payments that, due to DefaultRipple, were detected by our relayer as incoming…

Tx said it traced the stolen assets across chains and filed a formal complaint with the FBIs Internet Crime Complaint Center. The filing included transaction records and additional identifying information, according to the project. Filing an IC3 complaint does not by itself establish that the FBI has opened a criminal investigation.

The incident fits a wider security pattern. In related coverage, cross-chain bridge exploits have caused more than $4 billion in losses since 2021, with failures in cross-chain verification repeatedly providing attackers a route to unbacked assets.

What happens next for affected bridged XRP holders

Tx said it has identified and remedied the vulnerable code, but the XRPL bridge remains offline while the team reviews additional security changes. The project has not announced a date for restoring bridge operations.

The company is also evaluating ways to address losses for affected users and said it will publish a mechanism and timeline in a later update. For now, tx says holders do not need to take action and warned users against unofficial recovery services.

The next verified developments to watch are the final reconciliation of the stolen amount, any recovery or freezing of funds, the user remedy plan and the conditions for reopening the bridge. The team has also said it intends to pursue identification and prosecution of the attacker, but that outcome remains dependent on the continuing investigation and law enforcement process.

Read more:

FlightAware withdraws Kalshi lawsuit after flight market dispute

免責聲明

本文觀點僅代表作者個人觀點,不構成本平台的投資建議,本平台不對文章信息準確性、完整性和及時性作出任何保證,亦不對因使用或信賴文章信息引發的任何損失承擔責任
上一篇

ADI Chain 與 Shipfinex 合作,將價值 5 億美元的船舶項目儲備代幣化

下一篇

核心通胀数据成 7 月 CPI 报告关注焦点