Key Highlights
- Nearly 200,000 XRP was drained from the Coreum bridge during a 97-minute attack, leaving the bridge with only 493.5 XRP.
- A flaw in the bridge’s relayer system allowed fake deposits to be treated as legitimate and converted into real XRP withdrawals.
- The XRP Ledger was not compromised. The stolen XRP was released through transactions signed by the bridge itself before the bridge was halted.
Nearly 200,000 XRP was drained from the Coreum cross-chain bridge on August 9 after an attacker exploited a weakness in how the bridge checked deposits, according to on-chain analysis from XRPL.io.
The attack lasted 97 minutes, with 199,916.3 XRP sent out of the bridge between 19:16 and 20:53 UTC. As of now, the attacker has not been identified. According to XRPL.’s analysis published on Tuesday, the Coreum bridge account held about 200,410 XRP before the transfers began. After the activity stopped, only about 493.5 XRP remained.
The stolen XRP was distributed through 94 payments to two newly created wallets. Each payment was approved by 17 of the bridge’s 28 relayer keys, meaning the transfers were authorized through the bridge’s own signing system.
The first XRP release started with a payment of 3,249 XRP. Later, one transaction sent 25,908.6 XRP before the bridge settled into a pattern with smaller amounts sent into the two wallets. The last XRP transfer came at 20:53 UTC under transaction hash “CD308F….28020D”
Rippling was not behind the drain
The incident was initially linked by some community members to the XRP Ledger’s DefaultRipple setting, with early warnings suggesting that the feature could have enabled the drain. Later analysis found no evidence that rippling caused the loss.
Native XRP does not use trust lines and therefore does not move through the XRP Ledger’s rippling mechanism. The analysis also found that the XRP leaving the bridge was transferred through payments signed by the bridge itself. The evidence instead points to a failure in the bridge’s deposit-verification process.
The attacker exploited a deposit-checking flaw
The attack centered on the bridge’s wrapped Coreum token.
The attacker first moved the bridge’s own wrapped Coreum token between wallets they controlled. They added a memo containing information that looked like a normal bridge deposit. Because the bridge issued the token, those transactions appeared in its transaction history.
That is where the bridge’s checking system failed.
The relayers were responsible for watching the XRP Ledger and telling the Coreum network when a deposit had happened. But the relayer code checked that a payment was successful, looked at the amount, and read the recipient from the memo.
It did not properly check whether the money had actually been sent to the bridge. That small gap gave the attacker a way in.
Fake deposits led to real XRP withdrawals
The fraudulent transactions were subsequently reported to the bridge contract by multiple relayers. On Coreum, 21 relayers separately reported the first fake deposit to the bridge contract. The contract then gave the attacker a balance even though no real deposit had been made.
The attacker tested the method with small amounts before increasing the size. The first nine transactions “50E065…2B76BB” started with a small 92-unit probe and later increased through larger amounts.
The process eventually created roughly 4.36 million CORE and 200,001 XRP in bridge tokens. Those fake balances were then used through the normal withdrawal process, causing the bridge’s relayers to approve real XRP payments.
Stolen XRP was moved to other wallets
The stolen XRP did not stay in the first two wallets for long. Both wallets had been created less than two hours before the attack. They received about 107,397.5 XRP and 92,518.8 XRP before sending most of the funds onward. Another roughly 34,000 XRP moved to three other wallets.
The transaction pattern indicates that the attacker used newly created addresses to receive and redistribute the stolen funds after exploiting the bridge’s verification mechanism. No evidence from the analysis indicates that the XRP Ledger itself was compromised.
Bridge attack adds to broader crypto security concerns
The Coreum incident comes amid continued losses from exploits targeting crypto infrastructure.
Blockaid’s first-half security report recorded 212 on-chain exploits and more than $1.1 billion in losses during the first six months of the year. The report also pointed to a growing role for governance and process failures in crypto attacks.
Bridge infrastructure has been a major part of that trend. Earlier in 2026, KelpDAO suffered a $292 million bridge drain, while AFX Trade lost about $24.15 million after an attack on a third-party bridge. B² Network also lost about $3.86 million after an attacker gained control of upgrade authority over its staking contract.
The Coreum incident follows a different technical path but highlights a similar weakness: the failure occurred in the mechanism used to verify and authorize transactions rather than through a compromise of the underlying blockchain.
Also Read: Panther Protocol Hit by Governance Attack, 5.12M ZKP Drained on Base
