Cross-chain bridge tx on XRP Ledger lost $200,000: exploit details and parallel Harmony hack

On August 9, the bridge connecting the tx ecosystem to the XRP Ledger was subjected to a targeted attack. The attacker completely drained the bridge's reserve wallet, withdrawing about $200,000 in XRP. The incident exposed a critical vulnerability in the deposit processing logic, which allowed the system to accept fictitious transactions as real incoming funds.
The essence of the exploit was as follows: the bridge generated "wrapped" tokens on the tx network based on false deposit records where XRP was actually absent. Using these phantom assets, the hacker exchanged them for real coins from the vault. It is important to emphasize that the attack did not affect user funds on the mainnet, nor on centralized and decentralized exchanges — the damage was limited exclusively to the bridge's reserve pool.
According to my data, the withdrawal process took 97 minutes. During this time, 94 transactions were made from the bridge address to two new wallets, resulting in the balance dropping from ~200,410 XRP to a mere 493.5 XRP. Notably, each operation passed validation: 17 of 28 relay keys confirmed the payment, which met the established threshold. This indicates that the attacker did not hack private keys but manipulated the bridge's business logic itself, leaving the XRP Ledger fully operational.
The tx team responded promptly: the bridge was halted, the vulnerable code was fixed, and all transaction data was handed over to the FBI's Internet Crime Complaint Center. Developers are currently evaluating compensation options for affected users.
Parallel Strike: Harmony Back in the Spotlight
At the same time, the L1 blockchain Harmony suffered a separate hacker attack. According to my observations, the attacker used empty blocks to mint 4 billion ONE tokens, accounting for 26% of the total supply. Of this amount, 2.8 billion coins were immediately moved to trading platforms, triggering a price collapse of nearly 30%. The project team, together with exchanges, is working to freeze the stolen funds, also considering the possibility of a network rollback.
This is not the first incident for Harmony: in June 2022, the project already lost $100 million through the Horizon bridge when hackers gained control of a multisig wallet. At that time, experts from Elliptic and the FBI attributed the attack to the North Korean Lazarus group. The current incident likely has different roots, but the recurrence of vulnerabilities in cross-chain infrastructure raises serious questions about security standards in this niche.
My analysis: This case is yet another reminder that cross-chain bridges remain the most fragile point in the DeFi ecosystem. Even without key compromise, errors in deposit validation can lead to catastrophic consequences. Investors should reconsider their approach to storing assets on such bridges, favoring proven solutions with multi-layered audit verification.