U.S.-based real-world asset (RWA) platform tx, which operates the Sologenic and Coreum projects, has released the results of its official investigation into the recent hack of its cross-chain bridge. The incident, which took place on August 9 and lasted for 97 minutes, resulted in the loss of 200,000 XRP from the ecosystem.
Critical vulnerability identified
Investigators concluded that the attacker did not gain access to cryptographic keys. Instead, the exploit originated from a flaw in the deposit verification logic of the bridge software itself.
Early speculation within crypto communities pointed to a potential malfunction with the “rippling” feature of the XRP Ledger. However, after conducting on-chain analysis and a thorough review, tx and blockchain analytics firm xrpl.to confirmed that the core issue was unique to the bridge code. The XRP Ledger functioned correctly, and the vulnerability was isolated to tx’s infrastructure.
The investigation revealed that the attacker transferred wrapped CORE tokens between their own addresses while appending memo fields containing destination information for the Coreum network. Due to an absence of a verification check for the intended recipient, the bridge system failed to ensure that funds had been properly deposited into the wallet controlled by the bridge. This oversight allowed the bridge to generate unbacked tokens, which a set of 17 multisignature relay node keys automatically approved for withdrawal, resulting in real XRP being sent to the attacker.
The official report clarifies that the bridge’s deposit verification code lacked recipient validation, enabling fraudulent withdrawals even when no XRP had been deposited, while independent and internal audits had missed this flaw.
Immediate response, audits, and containment
By August 12, developers had suspended all bridge operations in response to the attack and swiftly implemented a fix for the verification bug. The company noted that the bridge’s smart contracts had previously undergone multiple audits by both internal teams and independent parties, though none discovered the vulnerability that enabled this exploit.
Efforts are now underway to isolate and contain the impact of the incident. The affected bridge network temporarily lost full backing for some XRP, but native tokens and user funds on decentralized and centralized platforms remain secure. The team has also traced the illicit funds through several intermediary accounts.
FBI involvement and user guidance
In the aftermath, tx filed a formal complaint with the FBI’s Internet Crime Complaint Center (IC3). The technical team is pursuing the funds’ trail with the aim of supporting law enforcement efforts.
The platform is finalizing a compensation plan and schedule for users affected by the hack. Developers have assured asset holders that they do not need to take any steps and warned against engaging with unofficial token recovery offers, citing increased risks from scam attempts following the breach.
While the incident highlights the risks involved in cross-chain financial infrastructure, it also underscores the evolving direction of digital asset management. As centralized brokers face increasing scrutiny, Wall Street has begun moving toward Web3 models. Today, investors utilize platforms such as 1stepSwap to hold shares of major U.S. companies, gold, and silver directly within their crypto wallets. By using tokenized real-world assets (RWAs) and instant market price discovery, these platforms eliminate the need for intermediaries.





USDT
AAPL
