XRP Bridge Drained After Software Treats Fake Deposits as Real - Decrypt
Tx said an attacker drained about 199,916 XRP (about $202,000) from the Tx XRPL bridge on Aug. 9 by exploiting deposit-detection logic that credited transactions without receiving XRP. The bridge minted unbacked XRP on Tx Chain, enabling swaps for real XRP. Tx halted the bridge, fixed code, and is tracing funds and seeking remedies.
How this was made
The 30-second read
Why it matters
The bridge credited transactions without receiving XRP, minted bridged XRP on Tx Chain, and used the bridge’s normal process to withdraw resulting unbacked balances; Tx halted the bridge, fixed code, traced funds, and filed an FBI IC3 complaint.
Market read
Traders should monitor bridge downtime, remediation timelines, and any follow-on security advisories that could affect XRP-related bridge flows and perceived settlement risk.
What to watch
User compensation mechanics, bridge downtime duration, and whether similar deposit-detection logic exists in other bridges could drive subsequent volatility more than the initial $202k loss.
Background
Tx operates a bridge between Tx Chain and the XRP Ledger; the exploit stemmed from deposit-detection logic that treated self-directed transactions as real deposits.
Ticker impact
Tx XRPL bridge credited fake deposits and minted bridged XRP, then released about 199,916 XRP via 94 payments, impacting XRP-USD risk.
Limited immediate price impact is implied, but elevated risk premium and volatility risk around bridge/relayer operations is likely.
The article reports a concrete exploit and halted bridge, but also states XRP price barely moved and hovers near $1, suggesting market impact may be more risk-based than fundamental.
Market effects
Highlights systemic smart-contract and cross-chain deposit-detection failure modes for XRPL bridge operators and relayer networks.
No clear regional linkage; primarily affects global crypto liquidity and bridge counterparty confidence.
Could increase scrutiny of cross-chain minting and relayer authorization models across major L1/L2 bridge ecosystems.
Counterpoint
Because XRP spot price barely moved and the exploit size is small versus XRP market cap, the event may be more contained operationally than market-wide fundamentally.
Key entities
- companyTx
Operator of the Tx XRPL bridge that halted operations after the deposit-detection flaw was exploited.
- platformXRPL
Independent XRP Ledger trading and analytics platform that analyzed the payments and disputed a 'rippling' explanation.
- serviceTornado Cash
Mixer to which the attacker allegedly sent stolen XRP after converting to Ethereum via THORChain.
- governmentFBI Internet Crime Complaint Center (IC3)
Law-enforcement intake channel Tx used to file a complaint regarding the exploit.


