What to Know
- Tx suspended its cross-chain bridge after investigators identified faulty deposit verification as the weakness behind the 200,000 XRP theft incident.
- Investigators found no compromised cryptographic keys, while manipulated wrapped CORE transactions allowed unbacked assets to drain genuine XRP from reserves.
- Tx fixed the verification flaw, contacted the FBI, traced stolen funds, and began preparing compensation arrangements for affected XRP holders.
U.S.-based RWA platform tx has suspended its cross-chain bridge and contacted the FBI over the theft of 200,000 XRP. Its investigation identified faulty deposit verification within the bridge software as the weakness responsible for the loss.
The August 9 exploit lasted 97 minutes and affected infrastructure supporting tx’s Sologenic and Coreum ecosystem. Investigators found no evidence that the attacker compromised cryptographic keys or exploited a vulnerability within the XRP Ledger.
Tx also rejected early theories that connected the incident with the XRP Ledger’s rippling feature. On-chain analysis from xrpl.to supported the company’s findings and placed the vulnerability entirely within the bridge software.
According to tx technical lead Reza Bashash, the attacker moved wrapped CORE tokens between addresses controlled by the same entity. Those transactions carried memos containing destination details that relay validators processed when verifying activity across the bridge.
However, the bridge lacked a mechanism for confirming whether transferred assets actually reached its designated wallet. Consequently, transactions could appear as legitimate deposits even when funds moved between addresses controlled by the attacker.
Also Read;Â Crypto Market Update: Bitcoin Slips Below $64K as BNB, XRP and DOGE Rally
Deposit Verification Flaw Exposes XRP Bridge Reserves
The verification weakness enabled the attacker to generate unbacked assets without depositing corresponding funds into the bridge wallet. Those assets then entered the normal withdrawal process, eventually allowing real XRP to leave the bridge reserves.
A quorum involving 17 multisignature keys held by relay nodes authorized withdrawals based on the manipulated transaction information. Significantly, investigators found no indication that the attacker gained direct access to any of those cryptographic keys.
Instead, the authorization system processed fraudulent deposits as legitimate because the underlying verification process failed to check recipients properly. This distinction places the security failure within bridge logic rather than the XRP Ledger or its cryptographic infrastructure.
Tx has completely suspended bridge operations while developers address the reserve imbalance and examine safeguards surrounding the affected infrastructure. Additionally, developers have corrected the recipient verification weakness identified during their investigation.
Several internal and independent security audits had previously examined the bridge’s smart contracts without detecting the flaw. Tx has since isolated the affected infrastructure to prevent the same weakness from causing further losses.
FBI Complaint and Compensation Plan Follow Investigation
Bridged XRP within the tx network temporarily lost full backing because real XRP left reserves during the exploit. However, native platform tokens and assets held across decentralized and centralized exchanges remained unaffected.
Moreover, tx traced the stolen XRP through several intermediary addresses while examining the attacker’s movement of funds. The company also filed an official complaint with the FBI’s Internet Crime Complaint Center regarding the theft.
Tx is developing a compensation mechanism and timeline for users affected by the reserve shortfall. Asset holders do not need to take additional steps while developers prepare the recovery arrangements. The company has also warned users against unofficial token recovery services seeking to exploit uncertainty surrounding the incident.
Conclusion
Tx’s investigation identified faulty bridge verification as the source of the 200,000 XRP theft. The platform has suspended bridge operations, fixed the identified weakness, involved the FBI, and started preparing compensation for affected users.
Also Read; XRP Macro Chart Signals Key Accumulation Zone as Egrag Crypto Maps $30 Expansion
