On August 9, the Coreum–XRPL bridge suffered a major exploit, with the bridge wallet dropping from roughly 200,410 $XRP to just 493.5 XRP.
In only 97 minutes, around 199,916 XRP was released through 94 payments to two newly created wallets.
But the most important part is HOW the attacker did it 👇
🔍 THE EXPLOIT
The attacker did not need to hack the XRP Ledger itself.
Instead, the vulnerability was inside the bridge's relayer logic.
The attacker moved the bridge's own wrapped tokens between two wallets controlled by him and attached a memo that looked like a legitimate bridge deposit.
The relayer software trusted that information and credited the attacker without properly verifying one critical condition:
➡️ Did the payment actually go to the bridge's deposit address?
Because that validation was missing, the attacker was able to create a fake deposit signal.
Once the bridge's internal accounting showed a balance that didn't actually exist, the attacker simply used the normal withdrawal mechanism.
The transactions were processed normally, with 17 of 28 relayer keys reportedly signing the payouts.
In other words:
✅ Valid signatures
✅ Normal withdrawal process
❌ False underlying deposit information
That distinction is extremely important.
⚠️ XRP LEDGER WAS NOT HACKED
The exploit was NOT a compromise of the XRP Ledger.
Native XRP itself has no issuer and does not use trust lines in the way issued tokens do.
So the viral explanation blaming "rippling" or the DefaultRipple flag does not explain this incident.
This was fundamentally a bridge/code-logic failure.
The blockchain continued operating normally.
The vulnerable software sitting on top of it did not.
💰 HOW MUCH WAS LOST?
Approximately:
• ~200,410 XRP initially held
• ~199,916 XRP released
• 94 payments
• ~97 minutes
• Only ~493.5 XRP remained
The activity also appears to have been prepared in advance.
Around 169,000 XRP was eventually routed toward two staging wallets that had reportedly been created on June 28 — weeks before the actual drain.
That suggests this was not simply a random opportunistic attack.
🛡️ WHAT WAS NOT COMPROMISED?
According to the information currently available:
▪️ XRP Ledger itself was not compromised
▪️ No evidence that XRP private keys were stolen
▪️ The bridge's software/logic was the primary vulnerability
▪️ Other bridged assets reportedly remain backed
The major user risk is therefore not native XRP.
The bigger concern is the backing and solvency of XRP representations on the affected bridge/chain.
🚨 THE BIGGER LESSON
This incident highlights one of crypto's biggest risks:
A blockchain can be secure while the infrastructure built around it is vulnerable.
Bridges introduce additional layers of:
• Smart-contract risk
• Relayer risk
• Multisig risk
• Accounting risk
• Verification risk
• Oracle/message-passing risk
Users often assume:
"Wrapped XRP = XRP"
But technically, they are not the same risk.
Native XRP exists directly on the XRP Ledger.
Wrapped/bridged XRP depends on another system correctly holding collateral and processing deposits and withdrawals.
If that system fails, the underlying blockchain can remain perfectly secure while the wrapped asset becomes undercollateralized.
📌 CURRENT STATUS
The bridge has reportedly been halted and the vulnerable code patched.
Forensics teams have been brought in and an FBI IC3 complaint has reportedly been filed.
However, at this stage, there is still no official post-mortem or confirmed compensation plan.
And importantly, the roughly $200K loss from this exploit should not automatically be used to explain XRP's broader price action.
The hack and the market's macro conditions are two separate issues.
📉 THE REAL TAKEAWAY
This wasn't an XRP Ledger failure.
It was a failure of verification logic in a bridge sitting on top of the ecosystem.
The attacker didn't break the blockchain.
He found a way to make the bridge believe something had happened when it hadn't — and then used the bridge's own withdrawal mechanism against it.
That's why bridge security matters just as much as blockchain security.
🔑 In crypto, "the blockchain is secure" does NOT automatically mean every application, bridge, wrapped asset or infrastructure layer connected to it is secure.
Always know what you're actually holding.

