Nearly 200,000 XRP has been drained from the Coreum XRPL Bridge after an attacker exploited a flaw in the bridge’s deposit-verification process, turning fraudulent deposits into genuine XRP withdrawals.
The attack took place on August 9 and lasted approximately 97 minutes. On-chain analysis shows that 199,916.3 XRP was transferred from the bridge between 19:16 and 20:53 UTC, leaving the bridge with only about 493.5 XRP from a balance of roughly 200,410 XRP before the attack.
The incident has raised fresh concerns about the security of cross-chain infrastructure, particularly the verification systems that sit between otherwise separate blockchain networks. However, the available evidence does not indicate that the XRP Ledger itself was compromised.
How the Coreum Bridge Attack Happened
The Coreum XRPL Bridge is designed to move assets between the XRP Ledger and Coreum. According to Coreum’s documentation, users can send XRP to an XRPL multisignature account and receive a corresponding representation of the asset on Coreum. Relayers monitor activity on both networks and submit information about transactions to the Coreum bridge contract.
That relayer architecture appears to have been at the center of the attack.
According to an on-chain investigation cited by multiple reports, the relayer software checked whether an XRP payment was successful, examined the amount involved and read information contained in the transaction memo. The critical problem was that it did not properly verify whether the XRP had actually been sent to the bridge’s designated deposit address.
That created an opportunity for the attacker to manufacture deposits without actually depositing the corresponding value into the bridge.
The attacker reportedly moved the bridge’s own wrapped Coreum token between wallets under their control and attached memo information that resembled a legitimate bridge deposit. Because the transactions involved an asset issued by the bridge, they appeared in the relevant transaction history. The missing destination-address check then allowed the relayers to interpret those transactions as legitimate deposits.
The result was effectively a false accounting entry.
The Coreum bridge credited the attacker with balances that were not backed by genuine deposits. Those balances could then be used through the normal withdrawal mechanism to request real XRP from the bridge’s XRPL reserves.
94 XRP Withdrawals Were Authorized by the Bridge
The scale and speed of the withdrawals illustrate how quickly a verification failure can become a major loss when it controls a pool of real assets.
Blockchain data indicates that the attacker received the stolen XRP through 94 payments sent to two newly created wallets. The transactions were not unauthorized transfers caused by a stolen bridge key. Instead, each payment was approved through the bridge’s existing multisignature authorization system. Reports indicate that 17 of the bridge’s 28 relayer keys signed each outgoing payment.
The first withdrawal was approximately 3,249 XRP. The attacker later triggered a transaction worth about 25,908.6 XRP before continuing with additional withdrawals. By the end of the 97-minute period, nearly the entire XRP balance held by the bridge had been removed.
This distinction is important.
The attacker apparently did not need to break the bridge’s multisignature wallet or obtain enough private keys to directly control the funds. Instead, the attacker manipulated the information being fed into the bridge’s accounting and verification process. Once the bridge believed that legitimate deposits had occurred, its own authorization mechanisms facilitated the withdrawals.
In other words, the security failure occurred before the final XRP payments were signed.
XRP Ledger Was Not the Source of the Exploit
Early discussion around the incident incorrectly linked the drain to XRP Ledger’s rippling functionality and the DefaultRipple setting.
Subsequent analysis found no evidence supporting that explanation. Native XRP does not use trust lines or an issuer in the way issued XRPL tokens do, meaning the conventional rippling mechanism was not responsible for the bridge’s XRP outflows. The XRP leaving the bridge was instead transferred through payments authorized by the bridge’s own multisignature system.
That makes the incident fundamentally different from an attack on the underlying XRP Ledger.
The XRP Ledger continued processing transactions normally. The weakness was in the infrastructure connecting XRPL to Coreum and, more specifically, in how that infrastructure determined whether a deposit had actually taken place.
This distinction matters for XRP holders because headlines describing the incident simply as an “XRP hack” could give the impression that XRP’s underlying network or consensus mechanism had been compromised. Current evidence does not support that conclusion.
Instead, the incident is another example of the risks created by cross-chain bridges, where the security of an asset transfer can depend on several separate components working correctly.
What the Exploit Means for Cross-Chain Security
The Coreum incident highlights a basic requirement for any bridge: a claimed deposit must correspond to an actual transfer of assets to the correct destination.
A transaction being valid is not enough.
A bridge must establish that the transaction involved the correct asset, the correct amount, the correct source and destination, and the correct bridge address before creating a corresponding balance on another network. If even one of those relationships is not verified, an attacker may be able to create assets or balances without providing the underlying collateral.
Coreum’s own documentation describes relayers as the infrastructure connecting the XRPL multisignature account with the Coreum bridge contract. The bridge therefore depends on those relayers correctly interpreting activity on the XRP Ledger and reporting it to the Coreum side.
The exploit demonstrates what happens when that interpretation contains a logical gap.
It also shows why multisignature security alone cannot eliminate bridge risk. In this case, the outgoing transactions were reportedly signed by the required relayer quorum. The problem was that the system was authorizing withdrawals based on fraudulent information that had already passed through the verification process.
A perfectly functioning signing system can still approve a bad transaction if the information presented to it is wrong.
The incident comes during a year in which bridge and cross-chain infrastructure has remained a major target for attackers. Security researchers and industry reports have documented large losses from attacks involving bridges, verification systems and other infrastructure connecting blockchain networks.
For Coreum, the immediate priority is therefore likely to be determining precisely how the verification logic allowed the fraudulent deposits, identifying whether the same weakness exists elsewhere in the bridge, and establishing how affected funds can be traced or potentially recovered.
What Happens Next for XRP and Coreum
The immediate impact is concentrated on the Coreum bridge rather than the XRP Ledger itself. Reports indicate that the bridge was halted after the attack, while the stolen XRP was traced through newly created wallets and subsequent transfers.
The attacker initially moved the funds into two wallets created shortly before the exploit. Those wallets received approximately 107,397.5 XRP and 92,518.8 XRP respectively, after which significant portions of the funds were moved onward to additional addresses.
At the time of reporting, the attacker had not been publicly identified.
For XRP, the bigger question is whether the incident has any lasting effect on confidence in cross-chain applications built around the asset. XRP is increasingly used across different blockchain environments and financial applications, but every bridge introduces additional infrastructure and therefore additional points of failure.
The Coreum incident reinforces that distinction.
The XRP Ledger can remain secure while an application built around it fails. A bridge can have functioning multisignature controls while still releasing funds based on incorrect information. And a transaction can be valid on-chain while the economic claim behind that transaction is fraudulent.
For investors, that makes the nearly 200,000 XRP loss more than a relatively small bridge hack. It is a reminder that the security of cross-chain XRP activity depends not only on the XRP Ledger, but also on the code, relayers, contracts and verification assumptions used by the applications connecting to it.
As investigations continue, the most important developments will be whether Coreum publishes a detailed post-mortem, identifies the exact code change required to close the verification gap, confirms the status of the bridge, and provides information about the stolen XRP.
For now, the evidence points to a Coreum bridge verification failure rather than an XRP Ledger failure. The attacker did not need to break XRP itself. They found a way to make the bridge believe that XRP had been deposited when it had not — and then used that false balance to withdraw almost all of the real XRP held by the bridge.















