200,000 XRP Lost in 97 Minutes: Who's to Blame?

Tue, 11/08/2026 - 8:54
On-chain data clears the XRP Ledger as a fatal logic flaw forces the TX bridge to validate fake deposits and authorize its own 200,000 XRP drain.
Advertisement
200,000 XRP Lost in 97 Minutes: Who's to Blame?
Cover image via depositphotos.com

Disclaimer: The opinions expressed by our writers are their own and do not represent the views of InkByte. The financial and market information provided on InkByte is intended for informational purposes only. InkByte is not liable for any financial losses incurred while trading cryptocurrencies. Conduct your own research by contacting financial experts before making any investment decisions. We believe that all content is accurate as of the date of publication, but certain offers mentioned may no longer be available.

Google
Advertisement

Two days after the incident, it emerged that the Coreum cross-chain bridge lost around 200,000 XRP during a 97-minute attack. Initial theories on social media linked the incident to a vulnerability in the XRP Ledger's "rippling" function. 

However, an analytical report from xrpl.to showed that the bridge effectively robbed itself by blindly trusting the attacker's transactions.

How 200,000 XRP got lost

Native XRP has no issuer or trust lines, so rippling is technically impossible for it. Moreover, every malicious payment was signed using the bridge's own legitimate multisignature, with a quorum of 17 out of 28 relayer keys, or validators. The hacker did not compromise the keys but simply created the illusion of a deposit for the validators.

HOT Stories
Bitcoin Miner Riot Secures Massive Deal With Anthropic XRP, Zcash (ZEC), Ethereum (ETH) and Bitcoin (BTC) Price Analysis For August 11: Market Reaction Is Uneven

First, the attacker moved their own wrapped tokens, or wrapped-CORE, between wallets they controlled, with a memo containing transfer details for Coreum attached to these transactions. Because the wrapped tokens had been issued by the bridge itself, the transfers appeared in its transaction history without any problems.

Advertisement
Article image
 Transaction mechanism analysis of the Coreum bridge exploit on the XRP Ledger, Source: xrpl.to

This was where the system's blind spot came into play. The relayer operators checked only whether a transfer had occurred and what was written in the memo field, while completely ignoring the recipient address. 

A check confirming that the funds had actually been sent to the bridge's wallet had simply never been added to the relayer code.

As a result, Coreum accepted the fake deposits and credited the hacker with a balance on its network. The attacker then requested a regular withdrawal, and the validators signed the transactions sending 200,000 real XRP from the bridge's XRPL wallet without hesitation.

Advertisement

You Might Also Like

The team responsible for the bridge's security has a long history of rebranding. It initially created the Sologenic (SOLO) project on the XRPL, then launched its own Layer 1 blockchain, Coreum, and in March 2026 merged both ecosystems under the U.S. brand TX, focused on the tokenization of real-world assets (RWAs).

The fact that a regulated U.S. company claiming institutional status could make such a basic mistake in its cross-chain verification logic damages TX's reputation more than the amount lost. 

It moves the question of who is to blame from the realm of a random bug to that of systemic quality control within the company.

What is happening to the tokens now?

At the time of writing, the TX team had still not released an official post-mortem report. The Coreum bridge remained completely suspended.

The hacker's identity remains unknown, but on-chain trackers are already seeing a classic attempt to cover their tracks. The stolen XRP is being rapidly distributed through a chain of transit wallets that were created a month and a half before the attack.

Advertisement
Advertisement
Advertisement
Advertisement
Subscribe to daily newsletter

Recommended articles

Our social media
There's a lot to see there, too
Advertisement