Simultaneously, the L1 blockchain Harmony was hacked.
The tx project team disclosed details of an attack on the cross-chain bridge connecting the $XRP Ledger to their blockchain. The malicious actor emptied the reserve wallet, stealing $200,000.
An update on the XRPL bridge incident.
— tx (@txEcosystem) August 11, 2026
On August 9, the tx XRPL bridge was exploited and $XRP was drained from the bridge's reserve wallet on the $XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. This...
The incident occurred on August 9. The attacker exploited a flaw in the deposit handling logic: the bridge accepted transactions without actual $XRP as real deposits. Based on these false records, the system issued 'wrapped' tokens on the tx network, and the hacker used them to withdraw real coins from the treasury.
The attack did not affect funds in the mainnet, on centralized or decentralized exchanges, the developers emphasized.
According to the xrpl.to service, the fund withdrawal took 97 minutes. During this time, almost 200,000 $XRP ($199,916) left the bridge's address in 94 transactions to two new wallets. The balance remained at 493.5 $XRP instead of the initial approximately 200,410. Each payment was confirmed by 17 out of 28 relayer keys — exactly the number required by the rules.

Analysts noted that the cybercriminal did not gain access to private keys, and the $XRP Ledger itself operated without failures.
After detecting suspicious activity, the tx team halted the bridge's operation, fixed the vulnerable code, engaged blockchain experts, and submitted all transaction data to the FBI's Internet Crime Complaint Center. The developers are now considering compensation options for affected users.
Harmony Hack
Simultaneously, the L1 blockchain Harmony suffered a hacker attack. The project team stated that it is working with exchanges to freeze the stolen funds and is considering network rollback options.
We are working with our team and appropriate exchanges to stop and freeze the funds.
— Harmony 💙 (@harmonyprotocol) August 12, 2026
We are working on a patch and rollback options.
Will update when we have new information. https://t.co/XB0nCwTAyN
An analyst under the nickname Juiceberg reported that through empty blocks, the malicious actor created 4 billion ONE — 26% of the token's total supply. Of these, 2.8 billion were transferred to trading platforms.
Amid the incident, the coin's price plummeted by almost 30%.

In June 2022, the project had already fallen victim to cybercriminals. At that time, Harmony lost assets worth $100 million. CertiK specialists indicated that the malicious actor "somehow" gained control over the platform's multisig wallet.
Elliptic analysts stated that the hack was carried out by hackers from North Korea. Later, the FBI came to a similar conclusion.
Recall that on August 10, unknown attackers targeted the Coinsbuy platform and stole $8 million. A few days earlier, cybercriminals emptied Lightning nodes via a vulnerability in BTCPay.
end-content




