0x485717704857…48571773
tx Bridge Loses ~200,000 XRP in 97-Minute Relayer Exploit
An attacker drained ~199,916 XRP from the XRP Ledger-to-tx bridge in 97 minutes on August 9, exploiting a relayer deposit-verification flaw that fired 94 withdrawals before the bridge was halted and an FBI IC3 report filed.
Outputs
Roughly 199,916.3 XRP (~$200,000) drained in 94 payments over 97 minutes on August 9, 2026, between 19:16 and 20:53 UTC.
Bridge reserve fell from ~200,410 XRP to 493.5 XRP; 17 relayers were responsible for verifying deposits.
Root cause was a relayer deposit-verification logic flaw that trusted memo formatting rather than confirming destination address and asset transfer on-chain.
The tx team disabled the bridge, hired forensics specialists, and filed a report with the FBI Internet Crime Complaint Center (IC3).
Cumulative bridge-hack losses exceed $2.8 billion since 2022, accounting for roughly 69% of all DeFi funds stolen in that span.
An attacker drained roughly 199,916 XRP from the cross-chain bridge connecting the XRP Ledger to tx (formerly Coreum) in 97 minutes on August 9, 2026, executing 94 sequential withdrawals that emptied a reserve holding about 200,410 XRP down to 493.5 XRP.
The exploit, worth approximately $200,000, hit the bridge's off-chain relayer software rather than the XRP Ledger itself. On-chain analysis from SlowMist and Cryptopolitan confirmed the drain running from 19:16 to 20:53 UTC.
What did the attacker actually break?
The bridge relied on 17 relayers, off-chain agents watching the XRP Ledger and authorizing matching releases on the tx side. Their job was to confirm a deposit had genuinely arrived before signing off on a payout.
The attacker didn't defeat that check cryptographically. They moved the bridge's own wrapped tokens between wallets they controlled and attached memos formatted to look like legitimate bridge deposits. The relayer code registered those self-transfers as inbound XRP and signed off on real withdrawals against deposits that had never happened.
The tx team said in a public statement that the bridge had passed both internal and third-party audits before launch. SlowMist's incident write-up framed the issue plainly: the relayer logic checked transaction memos without verifying the destination address or confirming that funds had actually moved into the bridge's control. That makes this a design flaw, not a cryptographic break.
How did the market read it?
XRP barely moved. The token held around $1.00 through mid-August, defending the support level it had maintained most of the year after sliding roughly 43% off its January 2026 peak of $2.41. BankXRP posted as on-chain analysts reconstructed the attack: "JUST IN: 200,000 XRP drained from the Coreum-XRPL bridge in 94 payments over 97 minutes on Aug 9. Root cause: a relayer logic flaw."
CoinDesk added its own alert, noting the bridge was "exploiting a flaw in the bridge's deposit verification to create fake balances and trigger real withdrawals."
Pricing the tx token itself is messier because of the Coreum-to-tx rebrand following the March 2026 merger with tokenization platform Sologenic. CoinStats listed tx near $0.006266 with a market cap of about $27.2 million, while CoinMarketCap's legacy Coreum listing showed $0.02020 and a $7.77 million cap. The split reflects the transition, not a clean market verdict.
Where does this fit in 2026's theft picture?
Small by bridge-hack standards. Ronin lost $624 million in March 2022, Wormhole $326 million in February 2022, and BNB Bridge $568 million in October 2022. Industry trackers put cumulative bridge-hack losses above $2.8 billion since 2022, roughly 69% of all DeFi funds stolen in that span.
The broader 2026 backdrop is heavier. CertiK's Hack3D report tallied $1,315,676,432 stolen across 344 on-chain incidents in the first half of the year, closing in on full-year 2025's roughly $3.4 billion total. PeckShield monitoring recorded about 30 major incidents in July 2026 alone, with combined losses near $210.3 million, a 177% jump from June's $75.87 million. The late-July Coldcard hardware-wallet exploit, in which attackers drained more than $100 million from wallets whose seed phrases had been generated with weak entropy, reinforced the same lesson: base chains hold, connective layers break.
What changes for bridge operators now?
The tx team disabled the bridge on August 9, began patching the verification code, brought in blockchain forensics specialists, and filed a report with the FBI's Internet Crime Complaint Center. As of mid-August, the team had not publicly detailed a reimbursement plan. Security researcher Radoslav Krehlik walked through the fake-deposit mechanism for a developer audience on LinkedIn, framing the failure as a prompt to re-verify that deposit confirmation logic checks destination address, asset type, and amount against actual chain state rather than a formatted message.
Expect mid-size bridges to absorb more scrutiny, automated circuit breakers to become a baseline expectation, and audit firms to market full-stack coverage that explicitly includes off-chain relayer code. The tx team has not given a public timeline for reopening the bridge.
via shattered.io (Original)