200,000 XRP Lost in 97 Minutes: Who’s to Blame?

0 1

200,000 XRP Lost in 97 Minutes: Who's to Blame?

Two days after the incident, it emerged that the Coreum cross-chain bridge lost around 200,000 $XRP during a 97-minute attack. Initial theories on social media linked the incident to a vulnerability in the $XRP Ledger’s “rippling” function.

However, an analytical report from xrpl.to showed that the bridge effectively robbed itself by blindly trusting the attacker’s transactions.

How 200,000 $XRP got lost

Native $XRP has no issuer or trust lines, so rippling is technically impossible for it. Moreover, every malicious payment was signed using the bridge’s own legitimate multisignature, with a quorum of 17 out of 28 relayer keys, or validators. The hacker did not compromise the keys but simply created the illusion of a deposit for the validators.

First, the attacker moved their own wrapped tokens, or wrapped-CORE, between wallets they controlled, with a memo containing transfer details for Coreum attached to these transactions. Because the wrapped tokens had been issued by the bridge itself, the transfers appeared in its transaction history without any problems.

200,000 XRP Lost in 97 Minutes: Who's to Blame?

Transaction mechanism analysis of the Coreum bridge exploit on the $XRP Ledger, Source: xrpl.to

This was where the system’s blind spot came into play. The relayer operators checked only whether a transfer had occurred and what was written in the memo field, while completely ignoring the recipient address.

A check confirming that the funds had actually been sent to the bridge’s wallet had simply never been added to the relayer code.

As a result, Coreum accepted the fake deposits and credited the hacker with a balance on its network. The attacker then requested a regular withdrawal, and the validators signed the transactions sending 200,000 real $XRP from the bridge’s XRPL wallet without hesitation.

The team responsible for the bridge’s security has a long history of rebranding. It initially created the Sologenic (SOLO) project on the XRPL, then launched its own Layer 1 blockchain, Coreum, and in March 2026 merged both ecosystems under the U.S. brand TX, focused on the tokenization of real-world assets (RWAs).

The fact that a regulated U.S. company claiming institutional status could make such a basic mistake in its cross-chain verification logic damages TX’s reputation more than the amount lost.

It moves the question of who is to blame from the realm of a random bug to that of systemic quality control within the company.

What is happening to the tokens now?

At the time of writing, the TX team had still not released an official post-mortem report. The Coreum bridge remained completely suspended.

The hacker’s identity remains unknown, but on-chain trackers are already seeing a classic attempt to cover their tracks. The stolen $XRP is being rapidly distributed through a chain of transit wallets that were created a month and a half before the attack.

Source

Leave A Reply

Your email address will not be published.