Coreum’s cross-chain bridge lost 199,916 XRP on Aug. 9 after an attacker exploited a flaw in the system’s deposit verification process, according to the source report and XRPL.io data cited in it. The funds were withdrawn over roughly 97 minutes and sent to two newly created wallets.
The incident left the bridge holding about 493.5 XRP. The report says the attacker was able to trigger XRP withdrawals without making legitimate deposits, pointing to a weakness in how the bridge validated incoming transactions rather than a failure of the XRP Ledger itself.
Withdrawals cleared through normal approvals
XRPL.io data cited in the report shows the bridge released the stolen funds through 94 separate XRP payments. Each of those transactions was approved by 17 of the bridge’s 28 relayer keys, meaning the withdrawals passed the bridge’s standard authorization flow.
That detail is significant because it suggests the exploit did not depend on seizing control of the bridge’s signing process. Instead, the attacker appears to have fed the system false signals that were accepted as valid deposit activity, allowing real XRP to be released.
How the deposit verification was allegedly bypassed
According to the report, the attacker first moved wrapped Coreum tokens among wallets under their control. They then attached a memo made to resemble a legitimate bridge deposit.
The bridge relayers reportedly checked whether the transactions had succeeded, the amount transferred, and the recipient named in the memo. But they did not verify that the matching XRP had actually been received by the bridge. That gap allegedly let the attacker manufacture deposit-like events and convert them into actual XRP withdrawals.
Funds sent to fresh wallets
The stolen XRP was moved to two newly created wallets, according to the source article. Over the course of about 97 minutes, the withdrawals reduced the bridge’s XRP balance to just 493.5 XRP.
The report also says the available evidence ruled out the XRP Ledger’s DefaultRipple setting as the cause of the loss. That narrows the focus to the bridge’s own checks and transaction handling rather than a broader issue with the underlying network.
Bridge exploits remain a wider industry problem
The Coreum incident fits into a broader pattern of bridge-related security failures across crypto infrastructure. The source article cites blockchain security platform Blockaid as recording 212 on-chain exploits in the first half of 2026, with losses topping $1.1 billion.
In this case, the attacker reportedly did not need to break the bridge’s core authorization model outright. Instead, the exploit worked by taking advantage of how the system interpreted deposits. The confirmed facts from the report point to the next key question for Coreum and bridge operators more broadly: how deposit verification logic is reviewed and strengthened to prevent false signals from unlocking real assets.
Source: Coin Edition