Crypto news

12.08.2026
06:17

Cross-chain bridge tx exploit: hacker drained XRP Ledger reserves of $200,000

XRP

On August 9, a serious attack occurred on the cross-chain bridge connecting the XRP Ledger ecosystem with the blockchain of the tx project. The attacker exploited a vulnerability in the logic of deposit processing, allowing them to withdraw about $200,000 from the bridge's reserve wallet. This is a classic case of exploiting trust in internal validation mechanisms, not a protocol-level hack.

The essence of the attack was that the bridge mistakenly accepted transactions without an actual XRP transfer as real incoming funds. Based on these fictitious records, the system generated "wrapped" tokens on the tx network, which the hacker then used to withdraw real coins from the vault. It is important to emphasize: funds on the mainnet, as well as on centralized and decentralized exchanges, were not affected. The XRP Ledger itself functioned without failures, and the attacker did not gain access to private keys.

According to the analytical service xrpl.to, the withdrawal of funds took 97 minutes. During this time, nearly 200,000 XRP ($199,916) was sent from the bridge address in 94 transactions to two new wallets. Only 493.5 XRP remained on the balance instead of the original ~200,410. Notably, each payment was confirmed by 17 of the 28 relay keys—exactly as many as required by the multisig rules. This indicates that the attacker acted within legitimate procedures but used them against the system itself.

The tx team responded promptly: they stopped the bridge's operation, fixed the vulnerable code, and brought in blockchain experts for analysis. All transaction data has been forwarded to the FBI's Internet Crime Complaint Center. Developers are currently considering compensation options for affected users.

Parallel attack on Harmony

During the same period, the L1 blockchain Harmony was subjected to a hacker attack. The project team announced joint work with exchanges to freeze stolen funds and is considering network rollback options. An analyst under the pseudonym Juiceberg reported that the attacker created 4 billion ONE through empty blocks—this is 26% of the token's total supply. Of these, 2.8 billion were transferred to trading platforms. Against the backdrop of the incident, the coin's price collapsed by nearly 30%.

Harmony has already faced similar problems: in June 2022, the project lost $100 million in assets as a result of the Horizon cross-chain bridge hack. At that time, CertiK specialists pointed to the attacker gaining control of the multisig wallet, while analysts from Elliptic and the FBI attributed the attack to North Korean hackers from the Lazarus Group.

These incidents once again raise the question of the reliability of cross-chain bridges, which remain one of the most vulnerable points in DeFi infrastructure. My verdict: until projects transition to more advanced validation models with dynamic confirmation thresholds and multi-level deposit verification, such attacks will continue to recur. Investors should closely monitor bridge security audits before placing significant liquidity there.