In brief
- An attacker drained nearly 200,000 XRP, worth around $202,000, from the Tx XRPL bridge.
- The bridge credited transactions that did not deliver XRP as deposits.
- Tx halted the bridge and is considering how to compensate affected users.
An attacker drained nearly 200,000 XRP, worth around $202,000, from an XRP Ledger bridge on August 9 by exploiting a flaw in its deposit-detection software, the project said.
In a post on X on Tuesday, Tx, which operates the bridge connecting the Tx Chain and the XRP Ledger, said a software flaw caused the bridge to record transactions as XRP deposits even though no XRP had been received.

“The attacker exploited the bridge's deposit-detection logic,” the company wrote. “The bridge's software incorrectly registered transactions that never actually delivered any XRP to the bridge as deposits, and minted bridged XRP on the tx chain against them.”
Tx is a layer-1 blockchain ecosystem launched in March by combining the Coreum blockchain with Sologenic, an XRP Ledger-based tokenization and trading platform.
The attacker used those fraudulent deposits to create unbacked XRP on the Tx Chain, then exchanged it through the bridge for real XRP.
According to Tx, the bridge underwent several internal and third-party audits before deployment, but the vulnerability was not identified.
XRPL, an independent XRP Ledger trading and analytics platform, found that the bridge released approximately 199,916 XRP through 94 payments over 97 minutes. Each payment was authorized by 17 of the bridge’s 28 relayers, programs that monitor both blockchains and approve transfers.
According to XRPL, the relayers mistook the attacker’s self-directed transactions for deposits. The attacker then withdrew the resulting unbacked balances through the bridge’s normal process.
The analysis rejected an initial claim that the XRP had been drained through “rippling,” an XRPL feature that moves issued tokens across trust lines. Native XRP cannot move through rippling, according to XRPL.
“A widely-shared warning blamed “rippling” and an on-by-default account flag. The ledger says otherwise: every one of those payments was signed by the bridge’s own multisig, and native XRP cannot be rippled at all,” XRPL wrote. “Reading both public chains together, the real cause is a relayer that mistook the attacker’s own self-payments for deposits.”



