An attacker drained close to 200,000 XRP from the Coreum cross-chain bridge within a quick span of 97 minutes on Aug. 9, exploiting a flaw in how the bridge confirmed deposits rather than any weakness in the XRP Ledger itself.
A cross-chain bridge connects two separate blockchains, letting users move assets between networks that cannot talk to each other directly.
The Coreum bridge let users lock XRP on the XRP Ledger and receive an equivalent number of tokens on Coreum's network.
According to on-chain analysis, the bridge held roughly 200,410 XRP before the incident and was left with just 493.5 XRP afterward.
Related: Major gold holder gives customers weeks before platform shutdown
How the funds drained out
Starting at 19:16 UTC, the bridge account sent out 94 payments totaling about 199,916.3 XRP to two newly created wallets over 97 minutes, finishing at 20:53 UTC.
Every transfer carried valid authorization: a group of relayers, nodes that monitor both chains and approve transfers, signed off, with 17 of 28 keys required for each payment.
Most Popular on TheStreet Roundtable:
The check that was missing
The problem sat in the bridge's verification logic. Relayers were meant to confirm that deposits were genuine before releasing funds, but one check was absent: the software never verified that a payment had actually been sent to the bridge itself.




