An attacker drained nearly 200,000 XRP tokens from the Coreum bridge in 97 minutes on August 9, exploiting a validation gap in the relayer software rather than any weakness in the XRP Ledger.
The bridge halted operations as XRP slid below $1 amid broader market caution.
What Actually Went Wrong on the Bridge
A blockchain bridge is an infrastructure that connects two separate networks. This allows users to move value between chains that cannot communicate directly. Relayers monitor both sides and authorize transfers.
Coreum Bridge lets users lock XRP on XRPL and receive an equivalent bridged version on the Coreum blockchain, which they can use in Coreum apps and later bridge back to XRPL.
So, how did the hack happen? The numbers tell a precise story. The bridge account held roughly 200,410 XRP before the incident and began releasing funds at 19:16 UTC.
Over 97 minutes, the account executed 94 payments totaling 199,916.3 XRP to two newly created wallets, leaving just 493.5 XRP behind.
Follow us on X to get the latest news as it happens.
Every transfer carried a valid authorization. A quorum of 17 out of 28 relayer keys signed each outgoing payment through the multi-signature process. Early social media explanations proved wrong. Warnings blamed rippling and the DefaultRipple flag, though native XRP cannot ripple because it has no issuer or trust lines.
The actual cause sat in the code. Relayers monitor XRP Ledger transactions and submit attestations whenever they detect payments carrying a Coreum-recipient memo.
One check was missing entirely. The software never verified that the payment destination was the bridge itself before crediting the corresponding balance. That omission opened the door.



