TX Crypto Bridge Drained of $200K in XRP Reserves Following Software Bug Exploit

The TX crypto bridge lost almost all its XRP reserves in a bug exploit on August 9. Attackers drained 199,916.3 XRP without stealing private keys by exploiting a validation flaw.

ICE•Author: Yosef Dolgopolsky
Source •
TX Crypto Bridge Drained of $200K in XRP Reserves Following Software Bug Exploit
Photo: ICE / קריפטו (צילום shutterstock)

The TX crypto bridge, formerly known as Coreum, lost nearly all of its XRP reserves on August 9 due to a software bug. Within approximately 97 minutes, 199,916.3 XRP coins, valued at about $200,000, were drained from the bridge. Following the attack, only 493.5 XRP remained in the bridge account, representing about 0.3% of the original reserve. According to CoinDesk, the bridge remains offline and the incident has been reported to US authorities.

The Anatomy of the Exploit

The unusual detail is that the bridge's signing key was not compromised. Each of the 94 approved transfers was a valid multisig transaction, signed by 17 out of the required 28 signers. In other words, the security mechanism itself worked as designed. The problem lay in the pre-approval phase: the bridge software checked the transaction history looking for transfers with a matching "MEMO" (a short message accompanying a transfer used for identification or data transmission), but the software failed to verify that the funds were actually sent to the bridge's address.

The vulnerability was made possible by the way the XRP Ledger network operates. When the default option is enabled, third-party transactions can appear in the account history even if the account itself did not directly initiate or receive them. The attacker exploited this behavior: they sent XRP to themselves, added the MEMO that the bridge was looking for to the transaction, and the system interpreted the action as a genuine deposit. It then executed the corresponding payment on the other side of the bridge.

Broader Impact and Laundering

The problem was not limited to XRP. According to reports, the same vulnerability also allowed the creation of about 4.36 million units of TX tokens, whose theoretical value was much higher than the actual available liquidity. Most of them were not sold. Some of the funds the attacker managed to extract were converted from XRP to Ethereum, routed through THORChain, and subsequently funneled to Tornado Cash, a service that obscures the connection between blockchain addresses.

The incident illustrates a critical vulnerability in cross-chain bridges: multi-signatures do not protect a system if the information on which a decision is based is flawed. In this case, no one needed to steal a private key. It was enough to send a transaction containing the details the software expected to see.

Following the attack, a complaint was filed with the FBI, the bridge remains suspended, and no user compensation plan has been announced to date.

Related News