A flaw in XRP Bridge allowed an attacker to create unbacked balances and withdraw XRP from the bridge's reserves, a vulnerability that went undetected during multiple audits. The incident raises fresh concerns about the security of cross-chain bridges and the effectiveness of the audits meant to protect them.
How the flaw worked
The vulnerability let the attacker generate balances that weren't backed by actual deposits, then use those phantom balances to pull XRP out of the bridge's reserves. The exact mechanics haven't been disclosed, but the result was a direct drain on the bridge's holdings. The attacker essentially created value out of thin air and cashed it out.
Why the audits missed it
The bridge had been reviewed by multiple auditors, yet none caught the flaw. That's a notable failure, given that audits are supposed to catch precisely this kind of issue. The fact that it slipped through suggests either a gap in the audit process or a bug subtle enough to evade standard checks. Either way, it's a black mark for the review teams involved.
The broader bridge problem
Cross-chain bridges have become a frequent target for attackers, and this incident adds to that pattern. The failure of audits to detect the vulnerability is a reminder that even code that's been vetted can harbor serious flaws. For users who rely on bridges to move assets between chains, the risk is hard to ignore.
The scale of the loss and the bridge's next steps remain unknown. The operators haven't released details on how much XRP was drained or what they plan to do about it. Until they do, the questions around this bridge's security — and the audits that missed the flaw — will hang in the air.




