CoinTrust

XRPL Bridge Exploit Drains Nearly 200,000 XRP

Ripple XRP Ledger

A software vulnerability in a blockchain bridge connecting the XRP Ledger to the tx blockchain allowed an attacker to create fraudulent deposits and withdraw nearly 200,000 XRP, worth about $200,000, from the bridge’s reserve wallet.

The incident exposed a weakness in the bridge’s deposit verification process, which incorrectly treated nonexistent transactions as legitimate deposits. By exploiting the flaw, the attacker was able to obtain bridged XRP that was not backed by corresponding assets held in the bridge’s reserves.

The attacker subsequently exchanged the unbacked tokens for genuine XRP, enabling the stolen assets to be removed from the bridge’s controlled reserves. The incident highlights the risks associated with blockchain bridges, which rely on software mechanisms to transfer or represent assets between otherwise separate networks.

The vulnerability allowed fraudulent deposits to be recognized as legitimate, resulting in the creation of unbacked bridged XRP that the attacker converted into genuine XRP from the bridge’s reserves.

Bridge Halted After Security Breach

The bridge operator responded by immediately suspending the service after identifying the exploit. Halting operations was intended to prevent additional fraudulent deposits and withdrawals while developers investigated the underlying software problem.

The operator subsequently fixed the vulnerability responsible for the incident. The technical remediation was aimed at preventing attackers from repeating the same process and generating additional unbacked assets.

The response also included the involvement of blockchain forensics specialists. Their role is expected to include tracking the movement of the stolen XRP, identifying addresses associated with the attacker, and helping establish how the funds were transferred following the initial withdrawal.

The operator also filed a complaint with the Federal Bureau of Investigation, bringing federal law enforcement into the investigation.

Stolen XRP Moves Through Multiple Addresses

A major challenge in recovering the assets is the speed at which the stolen XRP moved after the exploit. The funds were transferred through multiple blockchain addresses, making the movement of the assets more difficult to track and potentially complicating efforts to freeze or recover them.

Unlike traditional financial systems, blockchain transactions are generally designed to be irreversible once confirmed. Although transaction histories remain publicly traceable on many networks, identifying the individuals controlling specific addresses and recovering assets after they have been transferred can be difficult.

The movement of the XRP also creates uncertainty for users who may have been affected indirectly by the exploit. The operator has not yet established how holders of potentially affected bridged assets will be compensated.

Compensation Remains Unclear

The financial impact of the incident appears relatively limited compared with some larger blockchain exploits, but the episode raises broader questions about the safeguards used by cross-chain bridges.


Bridge operators must verify that assets deposited on one network actually exist before issuing corresponding assets on another network. A failure in that process can allow attackers to create tokens without providing the underlying collateral, potentially turning a technical flaw into a direct loss of reserve assets.

The incident underscores the importance of independent deposit verification, transaction validation, and continuous security monitoring for bridges that hold or transfer valuable digital assets across blockchain networks.


The operator’s decision to halt the bridge and repair the vulnerability reduces the immediate risk of further exploitation. However, determining the fate of the stolen XRP remains a separate challenge.

With the funds already distributed across multiple addresses, investigators and blockchain forensic specialists will need to trace the transaction trail and determine whether any of the assets can be identified or recovered.

The incident also leaves users waiting for clarity on compensation. Until the investigation establishes the full scope of the losses and the location of the stolen XRP, it remains uncertain whether affected holders will receive full reimbursement or whether another recovery mechanism will be adopted.

For the broader blockchain industry, the exploit serves as another reminder that cross-chain infrastructure can introduce significant security risks. Even when the underlying blockchain remains secure, vulnerabilities in the software connecting separate networks can expose reserves to unauthorized withdrawals and create losses for users and operators alike.

Exit mobile version