Due to a software bug that allowed an attacker to access deposits that were never made and withdraw real tokens using fake balances, the $XRP bridge lost nearly 200,000 $XRP, equivalent to approximately $200,000 at current prices.
The bridge connected the $XRP Ledger to a separate Coreum blockchain, which was renamed to the American tokenization company tx in March of this year. On August 9th, $XRP tokens left the bridge's reserve wallet over a 97-minute period, after which the system was halted.
The bridge is meant to operate as a vault with a receipt system. A user sends $XRP to a reserve wallet on the $XRP Ledger, and the bridge creates an equivalent amount of $XRP on the other blockchain. Returning those tokens allows the user to withdraw the real $XRP stored in reserve.
The attacker found a way to make the system issue receipts without putting anything into the vault.
According to data from tx, the bridge's software recorded transactions as deposits even though $XRP was never delivered to the bridge. This gave the attacker access to $XRP through the bridge on the tx blockchain without the real $XRP that should have backed it. These unbacked tokens were then returned through the bridge, and the attacker withdrew real $XRP from the reserve.

How a missing check allowed an attacker to withdraw $XRP that was never deposited into the account. Source: Shaurya Malwa.
The draining began at 19:16 UTC. Each payout was authorized by 17 of the bridge's 28 relayers, the majority of which confirmed it exactly as intended because the bridge's own records indicated the deposits were real.
Relayers are programs that monitor both blockchains and approve transfers when the bridge's records indicate a withdrawal is needed.
However, the specific bug affected one tier, as the relayer code processed payments containing the bridge's memo without first verifying the recipient's address.
tx confirmed the vulnerability in deposit detection in an update, reporting that the attacker used software that incorrectly recognized transactions that did not deliver $XRP to the reserve.
"Update on the XRPL bridge incident. On August 9th, the tx XRPL bridge was hacked and $XRP was drained from the bridge's reserve wallet on the $XRP Ledger. Bridge operation is paused, the vulnerability is identified, and all possible remediation avenues are being evaluated," wrote tx (@txEcosystem) on August 11, 2026.
The project added that they identified and fixed the vulnerable code, engaged blockchain forensics experts, and filed a complaint with the FBI's Internet Crime Complaint Center. They did not disclose how affected holders would be compensated.
Meanwhile, the stolen $XRP did not stay put. Blockchain tracking shows that the majority of it moved through several other addresses within a few hours.







