A cross-chain bridge connecting Tx Chain and the XRP Ledger recently had a vulnerability exploited, allowing attackers to siphon nearly 200,000 XRP by exploiting a flaw in the deposit identification process. The project team stated that the system incorrectly recorded transactions that had not actually been received as deposits, and subsequently generated bridged assets on the other chain without real asset backing.
The vulnerability lies in deposit recognition.
The transaction shows that the attack occurred on August 9. The attacker constructed transactions that appeared to complete deposits but did not actually transfer XRP to the cross-chain bridge address. The system subsequently still recognized these transactions as valid deposits and recorded the corresponding balances on the Tx Chain.
The attacker then used the standard withdrawal process to convert these unsupported balances into real XRP, thereby completing the fund transfer. The project team stated that the issue stemmed from the cross-chain bridge's deposit detection logic, not from user-side actions.
Transfer 199,900 XRP within 97 minutes
The independent XRP Ledger data and transaction analysis platform XRPL stated that the cross-chain bridge released approximately 199,916 XRP over 97 minutes, involving 94 payments, estimated at around $202,000 based on the price mentioned in the article.
According to XRPL analysis, the relay program of the bridge system misclassified the attacker's transactions as deposits. Each transfer requires authorization from 17 out of 28 relays, but this process failed to detect the anomalous transactions.
XRPL also denied earlier claims that the "rippling" feature caused the theft. The platform noted that native XRP does not transfer via the rippling mechanism, making it not the cause of this incident.
The project team has suspended services and is evaluating compensation.
The transaction indicates that the cross-chain bridge has been temporarily suspended, the relevant code has been fixed, the team has tracked the movement of the stolen funds, filed a report with the FBI’s Internet Crime Complaint Center, and engaged on-chain forensic firms and security partners to assist.
Reza Bashash, a partner at CoreNest Capital affiliated with Coreum and Sologenic, also stated that the attacker converted the stolen XRP into Ethereum via THORChain and then transferred all of it to the mixer Tornado Cash, making subsequent tracking more difficult.
Tx also stated that the team is evaluating remediation options for affected users. The cross-chain bridge will remain offline until it completes its security audit, and the project team has advised holders that no additional action is currently required, while warning users to be cautious of accounts or websites claiming they can recover funds on their behalf.
Additional information: Tx is a Layer 1 ecosystem launched in March this year, formed by the merger of the Coreum blockchain and Sologenic, a tokenization and trading platform built on the XRP Ledger. The project team stated that the cross-chain bridge underwent internal and third-party audits prior to launch, but this vulnerability was not detected at the time.


