An XRP bridge exploit update says 198,715.88 XRP was drained from a cross-chain bridge after an attacker took advantage of a flaw in the system’s relayer logic, according to reporting on the incident. The update frames the theft as the result of a weakness in how the bridge validated and processed deposits rather than a compromise of XRP itself.
What the XRP Bridge Exploit Update Confirms
The update centers on a single reported figure: 198,715.88 XRP was removed from the affected bridge. The loss is tied to the Coreum XRPL bridge, which connects the XRP Ledger to the Coreum network. For related coverage, see Binance Adds GLMR, ICX, MOVR, RARE and SOPH to Monitoring Tag.
Reporting attributes the drain to a relayer logic flaw, with one account describing how an attacker used a fake deposit to extract funds, according to CryptoPotato. Coverage from XRPL.to similarly attributes the drain to the bridge’s relayer handling. We have previously covered how the Coreum XRPL bridge lost nearly 200,000 XRP in this incident.
How a Relayer Flaw Could Enable an XRP Bridge Theft
A relayer is the off-chain component that watches for deposits on one chain and relays instructions so the corresponding assets are released or minted on the other. In the Coreum bridge, this logic is handled in code that processes XRPL-to-Coreum transactions. For related coverage, see OCC Chief Says Crypto Firms Can Pursue U.S. Bank Charters.
When a relayer accepts a deposit as valid without fully verifying it, an attacker can trick the bridge into crediting funds that were never genuinely deposited. This section is explanatory: the reporting attributes the loss to a relayer flaw, but the precise exploit path beyond the fake-deposit description is not fully detailed in the available update.
Bridge mechanics can also interact with XRP Ledger features such as rippling on fungible tokens, which governs how balances move through trust lines. Readers should treat the exact technical chain of events as still developing.
Why the Theft Matters for the XRP Ecosystem
The stolen asset is XRP, and bridge exploits like this one weigh on user trust in cross-chain infrastructure more than on any single token’s design. Similar concerns followed the SYND bridge exploit for $380K and the multi-chain exploit at Wasabi Protocol, both of which raised questions about bridge security.
The incident was flagged and tracked publicly, including by the txEcosystem account on X. Because this is framed as an update, further disclosures may clarify the scope, remediation, or recovery status; the details above reflect only what the current reporting supports.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.