The Coreum-XRPL bridge suffered a loss of nearly 200,000 XRP after an exploiter manipulated its transaction verification logic. XRPL.to, a blockchain analytics provider, reported that the attacker drained 199,916.3 XRP from the bridge on August 9 across 94 transactions spanning approximately 97 minutes. Before the incident, the bridge held roughly 200,410 XRP, leaving just 493.5 XRP remaining after the exploit.
Exploit details and transaction sequence
Unlike many bridge attacks involving key theft, this incident did not compromise validator keys or the XRP Ledger. Instead, the attacker leveraged a loophole in the bridge’s deposit verification mechanism. The withdrawals were processed with fully authorized multisignature approvals—requiring signatures from 17 of the bridge’s 28 relayer keys. There is no current indication of those keys being stolen.
Relayers are dedicated programs that observe blockchain activity on each side of the bridge and help process deposits and withdrawals between networks. These applications independently verify transactions and, upon reaching consensus, jointly authorize the release or credit of assets on the destination blockchain.
XRPL.to determined that the Coreum-XRPL bridge’s relayers misidentified certain transactions as valid economic deposits. The bridge operates by issuing a wrapped CORE token on the XRP Ledger. Since the bridge acts as the issuer, transactions involving the CORE asset can alter the bridge’s balances even if no actual value was deposited from an external source.
The attacker is believed to have conducted a series of transactions between wallets under their control, using memo formats that matched those expected by the bridge’s relayers. These operations mimicked genuine deposit events without transferring real assets into the bridge.
On one occasion, 21 relayers collectively submitted a single attacker-controlled transaction as a legitimate deposit to the Coreum contract. Through repeated use of this process, the exploiter generated an unbacked balance amounting to about 200,001 XRP and millions of CORE tokens, which could then be withdrawn by following standard bridge procedures.
Ultimately, the malicious actor converted this artificial balance into nearly all of the bridge’s real XRP reserves.
Mini dictionary: Relayers – Specialized software entities that monitor and relay information about blockchain activity between different networks, enabling cross-chain bridges to coordinate asset transfers securely.
Multisig protection and unanticipated vulnerabilities
The Coreum-XRPL bridge uses a multisignature system requiring 17 of 28 relayer signatures to approve withdrawals. While this threshold typically prevents unauthorized access to funds, it did not account for scenarios in which relayers jointly misinterpret deposits. All withdrawals initiated by the attacker were authorized by the bridge’s multisig system based on faulty, but valid, verification logic.
These findings highlight a little-known risk: implementing robust cryptographic controls may still leave bridges vulnerable if the underlying criteria for deposit validation are flawed. Accurate detection of true deposits is essential, and mere existence of a transaction is insufficient for cross-chain protocols handling real value.
To ensure the integrity of withdrawals, relayers must establish that the funds reached the correct accounts, matched intended asset types and amounts, and genuinely created economic deposits warranting corresponding withdrawals.
Relayers must not only verify that a transaction exists, but also confirm that assets have truly reached the intended destination, involved the proper amounts and tokens, and resulted in an authentic deposit mirroring the withdrawal request.
| Bridge Safeguard | Protection Provided | Weakness Exposed in Incident |
|---|---|---|
| 17-of-28 Multisig Approval | Prevents individual relayers from moving funds unilaterally | Does not guard against coordinated misinterpretation of deposits |
| Relayer Deposit Verification | Confirms qualifying transaction has occurred | Failed to confirm validity of asset flow and deposit authenticity |





USDT
AAPL
