An attacker exploited a software flaw to withdraw nearly 200,000 XRP by creating unbacked tokens on a linked blockchain.
A software vulnerability in an XRP bridge allowed an attacker to drain nearly 200,000 XRP, worth approximately $200,000, by generating fake deposits. The flaw enabled the bridge to recognize non-existent transactions as valid, issuing unbacked tokens that were later exchanged for real XRP from the reserve wallet.
The bridge, linking the XRP Ledger to the tx blockchain, was halted after the exploit was detected. The operator patched the vulnerability, engaged blockchain forensics experts, and filed a complaint with the FBI. The incident occurred over 97 minutes on August 9, with no immediate details on compensation for affected holders.
Bridges are designed to lock assets on one chain while issuing equivalent tokens on another. This exploit highlights risks in cross-chain infrastructure, particularly when software fails to validate deposits properly.