Coreum Cross-Chain Bridge Vulnerability Leads to 200,000 XRP Theft

icon币界网
Share
AI summary iconSummary
CFT protocols failed to prevent a $200,000 XRP theft from the Coreum cross-chain bridge, as a validation flaw allowed fake deposits to trigger real withdrawals. The attacker exploited memo field logic, initiating 94 withdrawals within 97 minutes. Coreum has paused the bridge pending a full investigation. Meanwhile, South Korean police arrested three individuals in connection with a fake XRP staking scheme. The XRP Ledger Foundation has issued a warning about MiCA-noncompliant scams impersonating Ripple.
CoinDesk reports:

A cross-chain bridge between Coreum and the XRP Ledger has been exposed with a vulnerability in its verification logic, resulting in approximately 200,000 XRP being withdrawn within 97 minutes. According to market analyst Xaif Crypto, the attacker did not obtain private keys or compromise the XRP Ledger itself, but instead exploited a flaw in the bridge’s relayer logic to initiate unauthorized withdrawals.

The issue lies in the relay verification.

The report states that the vulnerability lies in the bridge software's validation of transfer information. The system allegedly failed to properly verify the actual receiving address and instead relied on transaction remarks to determine whether a deposit was valid. This flaw could allow forged transactions to be mistaken as legitimate deposits, triggering the release of real XRP on the bridge.

The attackers allegedly initiated 94 consecutive payments within approximately 97 minutes, causing the bridge system to release real assets. According to this account, the infrastructure connecting Coreum and XRPL was affected, not the consensus mechanism or underlying cryptography of the XRP Ledger.

The bridging service has been suspended.

Reports indicate that the Coreum cross-chain bridge has been temporarily suspended, and a full investigation and incident report are still pending. Further analysis is expected to provide additional details on how the vulnerability was exploited and the destination of the transferred XRP.

Cross-chain bridges typically rely on relayers and verification systems to confirm whether assets have been genuinely deposited on one chain before releasing the corresponding assets on the other. If this verification process fails, attackers can still withdraw real funds through the bridge, even if the underlying blockchains are operating normally.

XRP users face dual risks

In addition to this technical incident, the report also mentioned that Seoul police in South Korea arrested three suspects accused of defrauding 71 investors through a fake Flare Network XRP staking project, involving approximately 3.4 million XRP.

The XRP Ledger Foundation previously warned users that scams are circulating on the market, falsely claiming to distribute XRP rewards under the Ripple name and tricking users into participating by scanning wallets. These two incidents demonstrate that XRP users currently face risks not only from software vulnerabilities but also from counterfeit projects and social engineering scams.

For market participants, the key takeaway from this event is that the alleged losses occurred at the bridge layer, not on the XRP Ledger mainchain itself. As more assets flow through bridges, custodial services, and peripheral applications, the verification design of this infrastructure is becoming one of the more vulnerable points in the crypto ecosystem.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.