Roughly 200,000 XRP disappeared from a cross-chain bridge in just 97 minutes, and on-chain data points to a fatal logic flaw in the bridge's validation code — not the XRP Ledger itself. The bridge, identified only as the TX bridge, authorized its own drain after accepting fake deposit proofs as genuine.
What the on-chain data shows
Investigators traced the loss to a single vulnerability in the TX bridge's deposit validation logic. The flaw allowed the bridge to treat fabricated deposit records as legitimate, then release funds from its own reserves. The XRP Ledger's core consensus and transaction processing were not involved in the error, according to the data.
The entire drain took under two hours. That speed suggests the attacker had already mapped the bridge's internal checks and knew exactly which fake deposit would pass.
Why the ledger isn't at fault
On-chain analysis clears the XRP Ledger of any direct responsibility. The ledger processed the outgoing transactions normally — the problem was upstream, in the bridge's software layer that decides what counts as a valid deposit. This distinction matters for users who might worry about the base network's security.
The bridge's logic flaw forced it to validate fake deposits, meaning the bridge itself became the attacker's tool. No external exploit of the ledger's protocol was used.
So far, no official statement from the TX bridge team has been released. The immediate question is whether the bridge will pause operations, refund affected users, or attempt to recover the funds. Given the 97-minute window, the attacker likely moved the XRP to multiple addresses quickly, which could complicate recovery.
For now, users holding XRP in similar bridges are left waiting for the TX bridge to disclose its next steps. The incident also raises a broader concern: if a single logic flaw can drain a bridge in under two hours, other bridges running similar code may need to audit their validation routines before they become the next target.


