Key Takeaways:
- TX lost 198,715.88 XRP in a 97-minute bridge exploit on Aug. 9
- Attackers exploited faulty deposit verification, not compromised keys
- FBI IC3 complaint filed; bridge remains offline pending security review
Key Takeaways:

TX lost 198,715.88 XRP in a 97-minute cross-chain bridge exploit on Aug. 9, after attackers abused faulty deposit detection logic to mint unbacked tokens.
"The vulnerability was in the bridge software rather than the XRP Ledger itself," Reza Bashash, technical lead at TX, said in the company's Aug. 12 post-mortem.
Initial theories in crypto communities linked the incident to the XRP Ledger's DefaultRipple feature, but analysis by xrpl.to and TX's own investigation disproved this hypothesis. Native XRP does not rely on trust lines or issuers, so rippling cannot apply to it. Instead, the attacker transferred wrapped-CORE tokens between wallets under their control, attaching memos with transfer instructions for the Coreum network. Relayer operators checked only whether a transfer occurred and read the memo field — they never verified the destination was the bridge vault. Once 21 relayers attested the first phantom deposit, the bridge's multisignature mechanism — requiring 17 of 28 validator signatures — approved withdrawals of real XRP from the reserve. Public ledger analysis traced 199,916.3 XRP leaving the bridge in 94 payments over 97 minutes.
The exploit exposes a systemic weakness in cross-chain verification for TX, a US-based RWA tokenization platform formed from the March 2026 merger of Sologenic and Coreum. The company filed a complaint with the FBI's Internet Crime Complaint Center and traced stolen funds through THORChain and Tornado Cash, but the bridge remains offline with no reopening date announced.
The attacker set up a series of transit wallets roughly six weeks before the exploit, suggesting premeditation. Stolen XRP was converted into ETH, moved to Ethereum through THORChain, and ultimately transferred to Tornado Cash, where direct tracing becomes more difficult.
TX said the bridge's smart contracts had undergone multiple rounds of internal and independent audits, none of which identified the flaw. The company described the incident as isolated to bridged XRP — other bridged assets remain fully backed, while bridged XRP on the TX chain currently lacks complete reserve backing.
The incident fits a wider pattern. Cross-chain bridge exploits have caused more than $4 billion in losses since 2021, with failures in cross-chain verification repeatedly providing attackers a route to unbacked assets.
TX said it has identified and remedied the vulnerable code, but the XRPL bridge remains offline while the team reviews additional security changes. The company is evaluating a compensation mechanism for affected users and said it will publish a timeline in a later update. TX warned users against unofficial recovery services as scam activity rises.
The company also said it intends to pursue identification and prosecution of the attacker, though that outcome depends on the ongoing investigation and law enforcement process. For the broader RWA sector, the incident raises questions about whether institutional-grade platforms can maintain adequate security standards as cross-chain infrastructure expands.
This article is for informational purposes only and does not constitute investment advice.