Cross-chain bridge tx attacked: hacker withdraws $200,000 in XRP, while Harmony suffers another blow

The cross-chain bridge ecosystem is once again demonstrating its vulnerability. This time, the bridge connecting XRP Ledger to the tx project's blockchain came under attack. The attacker exploited a critical flaw in the deposit processing logic and drained the reserve wallet, stealing approximately $200,000.
The incident occurred on August 9. The attacker discovered that the bridge accepted transactions without actual XRP as real deposits. Based on these false records, the system generated "wrapped" tokens on the tx network, which the hacker then used to withdraw real coins from the vault. It is important to emphasize: user funds on the mainnet, as well as on centralized and decentralized exchanges, were not affected.
Attack Details: 97 Minutes and 94 Transactions
According to my data, the withdrawal took 97 minutes. During this time, nearly 200,000 XRP (exact amount — $199,916) left the bridge address in 94 transactions to two new wallets. Only 493.5 XRP remained on the balance instead of the original ~200,410. Notably, each payment was confirmed by 17 of the 28 relay keys — exactly the number required by the multisignature rules. This indicates that the attacker did not gain access to private keys, and the XRP Ledger itself functioned without failures.
After detecting suspicious activity, the tx team promptly halted the bridge's operation, removed the vulnerable code, and brought in blockchain experts for an investigation. All transaction data has been forwarded to the FBI's Internet Crime Complaint Center. Developers are currently considering compensation options for affected users.
Harmony: A Second Blow and a 30% Crash
In parallel with the attack on tx, the L1 blockchain Harmony suffered a serious hack. The project team stated that it is working with exchanges to freeze the stolen funds and is considering a network rollback. An analyst under the alias Juiceberg reported that the attacker created 4 billion ONE through empty blocks — this is 26% of the token's total supply. Of these, 2.8 billion have already been transferred to trading platforms, triggering a price crash of nearly 30%.
This is not the first time Harmony has been hacked. In June 2022, the project already lost $100 million in assets as a result of an attack on the Horizon cross-chain bridge. At that time, CertiK specialists determined that the attacker gained control of a multisig wallet, and analysts from Elliptic and the FBI subsequently linked the hack to North Korean hackers from the Lazarus Group.
Against the backdrop of these events, one cannot help but recall other recent incidents: on August 10, unknown attackers hit the Coinsbuy platform, stealing $8 million, and a few days earlier, cybercriminals drained Lightning nodes through a vulnerability in BTCPay.
My comment: This series of attacks highlights a systemic security problem in DeFi. Vulnerabilities in transaction processing logic are not bugs but architectural miscalculations that require more thorough auditing and stress testing. Investors should reconsider their risks when using cross-chain bridges until the industry develops unified protection standards.