Crypto

XRP bridge drained after fake deposits triggered real withdrawals

Nearly 200,000 XRP was taken from the XRPL-to-tx bridge after a deposit-checking flaw issued unbacked tokens, according to tx.

Sofia Marchetti

By Sofia Marchetti · Columnist

· 3 min read

XRP bridge drained after fake deposits triggered real withdrawals
Photo: Decrypt

An XRP bridge drained of nearly 200,000 XRP, valued at about $200,000 in contemporaneous reporting, after software credited transactions that had not actually deposited XRP. For investors, the incident is a reminder that moving a token between blockchains can add risks outside the underlying network itself.

The affected service linked the XRP Ledger with Coreum, a separate blockchain that rebranded as tx in March, according to CoinDesk. The drain occurred on Aug. 9 and began at 19:16 UTC, with XRP leaving the bridge’s reserve wallet over 97 minutes before the service was halted, CoinDesk reported.

How did the XRP bridge drain happen?

A cross-chain bridge holds an asset in reserve on one blockchain and creates a matching representation on another. In this case, a user who deposited XRP into the bridge’s XRP Ledger reserve wallet would receive an equal amount of bridged XRP on tx. When that bridged XRP was returned, the system would release the original XRP from its reserve.

According to tx, the bridge’s deposit-detection software treated certain transactions as valid deposits even though no XRP reached the reserve wallet. CoinDesk reported that the code processed payments containing the bridge’s memo, a data field attached to a transaction, without first checking the destination address.

That error allowed the attacker to receive bridged XRP without supplying the XRP meant to back it. The attacker could then redeem those unbacked tokens through the bridge for genuine XRP held in the reserve, according to CoinDesk’s account.

The bridge used relayers, programs that monitor both networks and approve transfers. CoinDesk reported that 17 of 28 relayers authorized the payouts because the bridge’s own records incorrectly showed valid deposits. The reported failure was therefore in the software validation process feeding those relayers, rather than in the threshold approval mechanism itself.

Was the XRP Ledger compromised?

Available reporting points to a failure in the bridge’s software, not an attack on the XRP Ledger protocol. CCN reported that the information available did not indicate stolen private keys or a compromise of the XRP Ledger itself. A detailed official post-mortem had not been publicly indexed as of Aug. 12, so the technical reconstruction remains preliminary.

What has tx said it will do?

Tx said it halted the bridge, identified and fixed the vulnerable code, brought in blockchain-forensics specialists and filed a complaint with the FBI’s Internet Crime Complaint Center, according to CoinDesk. The company had not explained how holders affected by the incident would be compensated.

On-chain tracking reviewed by CoinDesk indicated that most of the stolen XRP moved through several addresses within hours. The central point for users is narrow: this incident involved a specific XRPL-to-tx bridge and its deposit checks, rather than XRP held on the XRP Ledger generally.

This story draws on original reporting from Decrypt.

More from Crypto

All Crypto