Particle.news
Download on the App Store

Relayer Bug Drains Nearly 200,000 XRP From tx/Coreum Bridge

Operator halted the bridge, patched the deposit‑verification code, filed an FBI complaint, leaving compensation and reopening timelines undecided.

Overview

  • A logic flaw in the bridge’s relayer software made self-payments look like real deposits and let an attacker trigger 94 legitimate multisig withdrawals that removed about 199,916.3 XRP over a 97-minute period on Aug. 9, 2026.
  • Each outbound payment carried the bridge’s multisignature approval with 17 of 28 relayer signatures, and on-chain analysis shows no evidence that relayer private keys or the XRP Ledger itself were compromised.
  • Blockchain tracing found most of the stolen XRP moved within hours into staging addresses, with roughly 169,000 XRP routed to two intermediary wallets and another ~34,000 XRP sent to three other addresses.
  • Tx has suspended the bridge, said it fixed the faulty destination‑verification check, hired forensic firms, and filed a complaint with the FBI, but it has not disclosed how users will be compensated or when the service might resume.
  • The breach highlights a wider risk in relayer‑based bridges that rely on off‑chain attestations rather than cryptographic proofs, a design choice that makes correct verification logic critical and raises the need for stricter audits and operational controls.