Tx halts its XRP Ledger bridge after an attacker exploits a software flaw to drain nearly 200,000 XRP in under two hours.
An attacker drained nearly 200,000 XRP, valued at approximately $202,000, from the Tx XRPL bridge by exploiting a flaw in its deposit-detection software. The bridge incorrectly registered transactions as deposits despite no XRP being delivered, allowing the attacker to mint unbacked XRP on the Tx Chain.
The breach occurred over 97 minutes, with 94 payments totaling 199,916 XRP released. Tx, which operates the bridge connecting the Tx Chain and XRP Ledger, stated the software underwent multiple audits but the vulnerability was missed. The project has halted the bridge and is evaluating compensation for affected users.
The incident highlights risks in cross-chain bridges, which have been frequent targets for exploits in decentralized finance.