200,000 XRP Gone In 97 Minutes. Here’s What Happened

Crypto analyst Xaif Crypto (@Xaif_Crypto) published a breakdown of one of the more striking bridge exploits in recent memory. On August 9, the Coreum bridge account on the XRP Ledger went from roughly 200,410 XRP to just 493.5 XRP. The XRP community has faced a growing wave of threats in recent months, including AI deepfake scams. However, no private keys were stolen in this case, and the XRP Ledger itself was never touched. However, almost 200,000 XRP disappeared in 97 minutes. 200,000 $XRP GONE in 97 minutes A logic flaw in Coreum's bridge let an attacker drain funds WITHOUT touching any private keys it only checked memos, not real destination addresses XRPL itself is safe. This was a bridge bug. Bridge is halted. Report still pending pic.twitter.com/ltZ2Ke6FZt — Xaif Crypto (@Xaif_Crypto) August 11, 2026 How the Attack Worked The Coreum bridge functions as an escrow between the XRP Ledger and the Coreum blockchain. Users lock XRP with the bridge, and relayers report that deposit to a smart contract on Coreum. The contract then mints wrapped XRP on the Coreum side. The relayers pay out whatever the contract records as owed. The attacker exploited that process. They moved the bridge’s own wrapped token between two wallets they controlled, tagging each transfer with a bridge memo. The relayer software read those transfers as legitimate deposits. It never verified whether a payment was actually sent to the bridge. The contract recorded a balance owed to the attacker. The relayers then co-signed 94 real XRP payments out of the bridge. Scammers targeting XRP have repeatedly shown a willingness to exploit process gaps. An attack from late 2025 included fake Xaman wallet support accounts that drained user funds through phone-based manipulation. In the Coreum attack, every payment carried authorization from 17 of the bridge’s 28 relayer keys. The bridge paid the attacker directly. The XRP Ledger recorded every transaction accurately. Tracing the Attack A warning during the drain blamed the account’s DefaultRipple flag, claiming XRP leaked through partial-payment loops. The on-chain data says otherwise. Native XRP has no trust line and cannot ripple. The bridge signed every payment. Zero XRP passed through via rippling. The two destination wallets were created less than two hours before the attack began. The attacker first sent nine wrapped-token transfers in a doubling pattern to confirm the exploit worked. Then 94 XRP payments followed. Both wallets forwarded nearly all funds within hours and now hold roughly 3 XRP each. We are on X, follow us to connect with us :- @TimesTabloid1 — TimesTabloid (@TimesTabloid1) June 15, 2025 XRP Is Safe Xaif was direct on this point: “XRPL itself is safe. This was a bridge bug.” The XRP Ledger processed every transaction exactly as signed.
عنوان اصلی (انگلیسی): 200,000 XRP Gone In 97 Minutes. Here’s What Happened
مشاهدهی خبر کامل در منبع ↗ بازگشت به Coreumاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.