{"id":37082,"date":"2026-08-12T11:34:25","date_gmt":"2026-08-12T11:34:25","guid":{"rendered":"https:\/\/bitunikey.com\/news\/xrp-bridge-exploit-update-tx-identifies-flaw-alerts-fbi\/"},"modified":"2026-08-12T11:34:55","modified_gmt":"2026-08-12T11:34:55","slug":"xrp-bridge-exploit-update-tx-identifies-flaw-alerts-fbi","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/xrp-bridge-exploit-update-tx-identifies-flaw-alerts-fbi\/","title":{"rendered":"XRP bridge exploit update: tx identifies flaw, alerts FBI"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">Tx said on Aug. 12 that its XRPL bridge was exploited on Aug. 9 after an attacker abused faulty deposit detection logic, draining XRP from the bridge reserve.\u00a0<\/p>\n<div id=\"cn-block-summary-block_0cbe8328bea83e22149df30c7b88f705\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Tx says attackers stole 198,715.88 XRP after exploiting a flaw in bridge deposit verification logic.<\/li>\n<li>The XRPL bridge remains halted while developers review security upgrades and possible user remedy options.<\/li>\n<li>Attackers converted stolen XRP into ETH before routing funds through THORChain and Tornado Cash afterward.<\/li>\n<li>Tx filed an FBI IC3 complaint with transaction records and additional identifying information about attackers.<\/li>\n<li>Other bridged assets remain fully backed, while bridged XRP currently lacks complete reserve backing.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>Technical lead Reza Bashash put the stolen amount at 198,715.88 XRP. The bridge remains halted while the team evaluates recovery options and strengthens the affected software, according to its latest <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/txEcosystem\/status\/2087269579190046895?s=20\" target=\"_blank\" rel=\"nofollow\">post<\/a>.<\/p>\n<p>The company said the flaw caused transactions that never delivered XRP to the bridge to be registered as deposits. This allowed unbacked bridged XRP to be minted on the tx chain. The attacker then withdrew real XRP from the reserve wallet against those balances.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<h2 class=\"wp-block-heading\"><strong>Tx says destination checks failed in the bridge relayer<\/strong><\/h2>\n<p>Tx said the vulnerability was in the bridge software rather than the XRP Ledger itself. Bashash described the issue as a bug in XRPL relayer logic involving cross currency payments and the DefaultRipple feature. The central failure, according to both the company and independent ledger analysis, was insufficient destination validation.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">An update on the XRPL bridge incident.<\/p>\n<p>On August 9, the tx XRPL bridge was exploited and XRP was drained from the bridge&#8217;s reserve wallet on the XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. This\u2026<\/p>\n<p>\u2014 tx (@txEcosystem) <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/txEcosystem\/status\/2087269579190046895?ref_src=twsrc%5Etfw\">August 11, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>The relayers accepted transactions carrying the expected bridge memo without confirming that the destination was actually the bridge vault. Once enough relayers attested to those false deposits, the tx side bridge logic credited unbacked balances that could be redeemed for genuine XRP.<\/p>\n<p>As previously reported, public ledger analysis traced 199,916.3 XRP leaving the bridge in 94 payments over 97 minutes. That earlier figure measures XRP released from the reserve, while Bashash now says 198,715.88 XRP was stolen. Tx has not publicly explained the roughly 1,200 XRP difference between the figures.<\/p>\n<h2 class=\"wp-block-heading\"><strong>DefaultRipple did not itself drain native XRP<\/strong><\/h2>\n<p>Earlier discussion of the incident focused on DefaultRipple, an XRP Ledger setting that applies to issued assets. XRPL.to\u2019s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/xrpl.to\/insights\/coreum-bridge-xrp-drain\" target=\"_blank\" rel=\"nofollow\">analysis<\/a> found that native XRP did not leave through rippling. Instead, all observed XRP releases were signed by the bridge\u2019s own multisignature setup.<\/p>\n<p>The analysis found 17 of 28 relayer signatures on the bridge payouts and 21 relayers attesting the attacker\u2019s first phantom deposit. That evidence points to shared verification logic accepting invalid input rather than stolen signing keys.<\/p>\n<p>The distinction matters because tx described the incident as \u201cisolated\u201d to bridged XRP. Other bridged assets remain fully backed, according to the company. Bridged XRP on the tx chain is not currently fully backed, and the team has not yet announced a reimbursement mechanism.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Stolen XRP moved through THORChain and Tornado Cash<\/strong><\/h2>\n<p>Bashash said the stolen XRP was converted into ETH, moved to Ethereum through THORChain and ultimately transferred to Tornado Cash. Direct tracing becomes more difficult after funds enter the privacy protocol, although investigators can still examine the transaction history leading to that point.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">The bridge between the TX Chain and XRP Ledger (XRPL) was exploited due to a bug in the XRPL relayer logic combined with the XRPL DefaultRipple feature.<\/p>\n<p>The attacker constructed cross-currency XRPL payments that, due to DefaultRipple, were detected by our relayer as incoming\u2026 <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/t.co\/x3JAIGRJys\">https:\/\/t.co\/x3JAIGRJys<\/a><\/p>\n<p>\u2014 Reza Bashash (@rezabashash) <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/rezabashash\/status\/2087280594069926266?ref_src=twsrc%5Etfw\">August 11, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>Tx said it traced the stolen assets across chains and filed a formal complaint with the FBI\u2019s Internet Crime Complaint Center. The filing included transaction records and additional identifying information, according to the project. Filing an IC3 complaint does not by itself establish that the FBI has opened a criminal investigation.<\/p>\n<p>The incident fits a wider security pattern. In related coverage, cross-chain bridge exploits have caused more than $4 billion in losses since 2021, with failures in cross-chain verification repeatedly providing attackers a route to unbacked assets.<\/p>\n<h2 class=\"wp-block-heading\"><strong>What happens next for affected bridged XRP holders<\/strong><\/h2>\n<p>Tx said it has identified and remedied the vulnerable code, but the XRPL bridge remains offline while the team reviews additional security changes. The project has not announced a date for restoring bridge operations.<\/p>\n<p>The company is also evaluating ways to address losses for affected users and said it will publish a mechanism and timeline in a later update. For now, tx says holders do not need to take action and warned users against unofficial recovery services.<\/p>\n<p>The next verified developments to watch are the final reconciliation of the stolen amount, any recovery or freezing of funds, the user remedy plan and the conditions for reopening the bridge. The team has also said it intends to pursue identification and prosecution of the attacker, but that outcome remains dependent on the continuing investigation and law enforcement process.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Tx said on Aug. 12 that its XRPL bridge was exploited on Aug. 9 after an attacker abused faulty deposit detection logic, draining XRP from the bridge reserve.\u00a0 Summary Tx&hellip;<\/p>\n","protected":false},"author":1,"featured_media":16502,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-37082","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/37082","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=37082"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/37082\/revisions"}],"predecessor-version":[{"id":37083,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/37082\/revisions\/37083"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/16502"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=37082"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=37082"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=37082"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}