XRP bridge exploit update: tx identifies flaw, alerts FBI
Tx said on Aug. 12 that its XRPL bridge was exploited on Aug. 9 after an attacker abused faulty deposit detection logic, draining XRP from the bridge reserve.
- Tx says attackers stole 198,715.88 XRP after exploiting a flaw in bridge deposit verification logic.
- The XRPL bridge remains halted while developers review security upgrades and possible user remedy options.
- Attackers converted stolen XRP into ETH before routing funds through THORChain and Tornado Cash afterward.
- Tx filed an FBI IC3 complaint with transaction records and additional identifying information about attackers.
- Other bridged assets remain fully backed, while bridged XRP currently lacks complete reserve backing.
Technical lead Reza Bashash put the stolen amount at 198,715.88 XRP. The bridge remains halted while the team evaluates recovery options and strengthens the affected software, according to its latest post.
The company said the flaw caused transactions that never delivered XRP to the bridge to be registered as deposits. This allowed unbacked bridged XRP to be minted on the tx chain. The attacker then withdrew real XRP from the reserve wallet against those balances.
Tx says destination checks failed in the bridge relayer
Tx said the vulnerability was in the bridge software rather than the XRP Ledger itself. Bashash described the issue as a bug in XRPL relayer logic involving cross currency payments and the DefaultRipple feature. The central failure, according to both the company and independent ledger analysis, was insufficient destination validation.
The relayers accepted transactions carrying the expected bridge memo without confirming that the destination was actually the bridge vault. Once enough relayers attested to those false deposits, the tx side bridge logic credited unbacked balances that could be redeemed for genuine XRP.
As previously reported, public ledger analysis traced 199,916.3 XRP leaving the bridge in 94 payments over 97 minutes. That earlier figure measures XRP released from the reserve, while Bashash now says 198,715.88 XRP was stolen. Tx has not publicly explained the roughly 1,200 XRP difference between the figures.
DefaultRipple did not itself drain native XRP
Earlier discussion of the incident focused on DefaultRipple, an XRP Ledger setting that applies to issued assets. XRPL.to’s analysis found that native XRP did not leave through rippling. Instead, all observed XRP releases were signed by the bridge’s own multisignature setup.
The analysis found 17 of 28 relayer signatures on the bridge payouts and 21 relayers attesting the attacker’s first phantom deposit. That evidence points to shared verification logic accepting invalid input rather than stolen signing keys.
The distinction matters because tx described the incident as “isolated” to bridged XRP. Other bridged assets remain fully backed, according to the company. Bridged XRP on the tx chain is not currently fully backed, and the team has not yet announced a reimbursement mechanism.
Stolen XRP moved through THORChain and Tornado Cash
Bashash said the stolen XRP was converted into ETH, moved to Ethereum through THORChain and ultimately transferred to Tornado Cash. Direct tracing becomes more difficult after funds enter the privacy protocol, although investigators can still examine the transaction history leading to that point.
Tx said it traced the stolen assets across chains and filed a formal complaint with the FBI’s Internet Crime Complaint Center. The filing included transaction records and additional identifying information, according to the project. Filing an IC3 complaint does not by itself establish that the FBI has opened a criminal investigation.
The incident fits a wider security pattern. In related coverage, cross-chain bridge exploits have caused more than $4 billion in losses since 2021, with failures in cross-chain verification repeatedly providing attackers a route to unbacked assets.
What happens next for affected bridged XRP holders
Tx said it has identified and remedied the vulnerable code, but the XRPL bridge remains offline while the team reviews additional security changes. The project has not announced a date for restoring bridge operations.
The company is also evaluating ways to address losses for affected users and said it will publish a mechanism and timeline in a later update. For now, tx says holders do not need to take action and warned users against unofficial recovery services.
The next verified developments to watch are the final reconciliation of the stolen amount, any recovery or freezing of funds, the user remedy plan and the conditions for reopening the bridge. The team has also said it intends to pursue identification and prosecution of the attacker, but that outcome remains dependent on the continuing investigation and law enforcement process.