Newsroom
11 August, 2026 / News / AI / Tags: xrp, coreum, bridge, relayers, attacker

A verification flaw in the Coreum bridge allowed an attacker to create fake deposits and withdraw real XRP, prompting a full suspension of the cross-chain service
An attacker drained approximately 200,000 XRP from the Coreum bridge on the XRP Ledger on August 9, 2026, in a rapid sequence of transactions lasting 97 minutes. The bridge account held about 200,410 XRP before the incident and was left with just 493.5 XRP after 94 outgoing payments totaling 199,916.3 XRP.
Blockchain analysis showed the XRP Ledger itself was not compromised. Every payment listed the bridge account as the sender and carried signatures from 17 of its 28 relayer keys, meeting the required multisignature threshold. The master key had been disabled, so the transfers relied entirely on the legitimate multisig process.
The root cause lay in the bridge’s deposit-checking logic on the Coreum side. Relayers monitor the XRP Ledger for incoming deposits and report them to a Coreum smart contract. Once enough relayers submit matching evidence, the contract issues wrapped assets.
The relayer code looked for successful payments in the bridge account’s transaction history that included a Coreum recipient memo. It did not confirm that the payment had actually been sent to the bridge’s designated address. This omission proved decisive.
The attacker transferred the bridge’s own wrapped-CORE tokens between two wallets under their control, attaching a memo that mimicked a legitimate deposit. Because the bridge had issued those tokens, the transfers appeared in its transaction history. Twenty-one relayers treated the movements as valid deposits and reported them to the Coreum contract.
The attacker first tested the system with a 100-unit transfer, then increased the amounts in a roughly doubling pattern. The process ultimately created roughly 4,356,812 CORE and 200,001 XRP equivalent in bridge tokens without any genuine deposits. The attacker then used those credited balances to request withdrawals of real XRP.
Those two wallets, opened less than two hours before the first payment, received approximately 107,397.5 XRP and 92,518.8 XRP respectively. Most of the funds were later moved in batches of roughly 9,600 to 9,720 XRP to older staging addresses created on June 28, 2026.
Early speculation linked the drain to the XRP Ledger’s DefaultRipple setting. Analysis rejected that theory. Native XRP has no issuer and does not use trust lines, so rippling cannot apply. None of the outgoing transactions used the partial-payment flag. The bridge itself authorized every transfer through its own multisignature process.
No private keys were stolen. The shared verification logic used by the relayers allowed the same false deposit reports to be accepted simultaneously, enabling the withdrawals.
The Coreum bridge was suspended the following afternoon and remained offline while investigators traced the funds through intermediary wallets. At the time of reporting, no official post-mortem had been released identifying the attacker or detailing any corrective measures beyond the suspension.
The incident involves TX, the U.S.-based entity that brought Coreum and the Sologenic ecosystem under one brand in March 2026 with a focus on real-world asset tokenization. The failure of a basic recipient-address check in its cross-chain infrastructure has drawn attention to the quality of its verification controls.
XRP traded near the $1 level in the days after the event, briefly touching $0.9905 before recovering to close around $1.01. The token stood more than 70 percent below its July 2025 peak of $3.66.









