On August 9, the bridge linking XRP Ledger and Coreum lost 198,715.88 XRP to an exploit. The attacker tricked the deposit-checking system into treating a wallet-to-wallet transfer as a real deposit, then withdrew real XRP. The bridge has been halted.
How the exploit worked
The attacker used the bridge's own wrapped token between two wallets with a deposit memo. That caused relayers to approve and mint unbacked assets. Then the attacker withdrew real XRP. The failure was traced to Coreum-side software, not XRP Ledger. Twenty-one separate Coreum relayers attested to the same phantom deposit, allowing repeated minting.
What tx said
Tx confirmed the exploit and filed a report with the FBI's IC3. No other bridged assets were affected. A compensation plan is being worked out.
The wrong explanation
Initially, the DefaultRipple explanation was floated, but that was incorrect. The real cause was the relayers' valid multisignature. That detail matters because it points to a systemic flaw in how the bridge validates deposits.
Market backdrop
XRP was already sliding this week, near $1.02, down 4.4%. Bitcoin hovered around $64,000, and the broader market shed $40 billion. The exploit adds to the pressure.
The bridge remains halted while tx works out compensation. The FBI report is in. The question now is whether the relayers' multisignature process gets a fix before the bridge reopens.



