Nearly 200,000 XRP drained from Coreum cross-chain bridge exploit

1 hour ago 9

The Coreum cross-chain bridge connecting to the XRP Ledger got gutted on August 9, losing approximately 199,916 XRP in under two hours. The bridge’s balance dropped from roughly 200,410 XRP to a lonely 493.5 XRP.

The exploit didn’t involve a breach of XRPL itself or the theft of any private keys. Instead, the attacker found a flaw in the bridge’s relayer logic that treated fake deposit actions as the real thing, triggering legitimate XRP withdrawals from the bridge’s wallet on the other side.

How the attack worked

Cross-chain bridges hold assets on one chain and issue equivalent tokens on another. The Coreum bridge used a multisig relayer system, where a group of relayer nodes collectively authorize transactions, to manage this process between XRPL and Coreum’s ecosystem.

The vulnerability lived in the deposit verification process. The bridge’s relayer logic was supposed to confirm that deposits on one chain were genuine before authorizing withdrawals on another. The attacker was able to submit fabricated deposit actions that the system accepted as legitimate, which then triggered real XRP payouts from the bridge’s XRPL wallet.

On-chain analysis showed 94 multisig-authorized payment transactions executed across a 97-minute window, from 19:16 to 20:53 UTC. The authorization required 17 of 28 relayer keys to sign off, meaning the exploit successfully fooled the consensus mechanism into approving nearly a hundred illegitimate transactions in rapid succession.

The bridge goes dark

As of August 11, the Coreum bridge remained suspended. The Coreum Development Foundation had not yet released an official incident report, leaving the community to piece together what happened through on-chain data and independent analysis.

The bridge originally launched on March 20, 2024, with an ambitious goal of connecting XRPL to over 110 IBC-compatible chains. IBC, or Inter-Blockchain Communication, is the protocol standard used across the Cosmos ecosystem that allows different blockchains to talk to each other. Coreum positioned itself as a gateway for XRP holders to access DeFi opportunities across that broader network.

What this means for cross-chain security

The core issue, relayer-based verification rather than on-chain cryptographic proofs, is a design choice that trades security for simplicity. Bridges that rely on a set of relayers to attest that something happened on another chain are fundamentally trusting those relayers and the logic governing them to be honest and accurate. When the verification logic has a bug, as it did here, the entire security model collapses.

The fact that no XRPL private keys were compromised and the ledger itself was unaffected will likely limit the fallout for the broader XRP ecosystem. This was a third-party infrastructure failure, not a protocol-level vulnerability.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article