A cross-chain bridge between Coreum and the XRP Ledger has been exposed with a vulnerability in its verification logic, resulting in approximately 200,000 XRP being withdrawn within 97 minutes. According to market analyst Xaif Crypto, the attacker did not obtain private keys or compromise the XRP Ledger itself, but instead exploited a flaw in the bridge’s relayer logic to initiate unauthorized withdrawals.
The issue lies in the relay verification.
The report states that the vulnerability lies in the bridge software's validation of transfer information. The system allegedly failed to properly verify the actual receiving address and instead relied on transaction remarks to determine whether a deposit was valid. This flaw could allow forged transactions to be mistaken as legitimate deposits, triggering the release of real XRP on the bridge.
The attackers allegedly initiated 94 consecutive payments within approximately 97 minutes, causing the bridge system to release real assets. According to this account, the infrastructure connecting Coreum and XRPL was affected, not the consensus mechanism or underlying cryptography of the XRP Ledger.
The bridging service has been suspended.
Reports indicate that the Coreum cross-chain bridge has been temporarily suspended, and a full investigation and incident report are still pending. Further analysis is expected to provide additional details on how the vulnerability was exploited and the destination of the transferred XRP.
Cross-chain bridges typically rely on relayers and verification systems to confirm whether assets have been genuinely deposited on one chain before releasing the corresponding assets on the other. If this verification process fails, attackers can still withdraw real funds through the bridge, even if the underlying blockchains are operating normally.
XRP users face dual risks
In addition to this technical incident, the report also mentioned that Seoul police in South Korea arrested three suspects accused of defrauding 71 investors through a fake Flare Network XRP staking project, involving approximately 3.4 million XRP.
The XRP Ledger Foundation previously warned users that scams are circulating on the market, falsely claiming to distribute XRP rewards under the Ripple name and tricking users into participating by scanning wallets. These two incidents demonstrate that XRP users currently face risks not only from software vulnerabilities but also from counterfeit projects and social engineering scams.
For market participants, the key takeaway from this event is that the alleged losses occurred at the bridge layer, not on the XRP Ledger mainchain itself. As more assets flow through bridges, custodial services, and peripheral applications, the verification design of this infrastructure is becoming one of the more vulnerable points in the crypto ecosystem.

