Coreum-XRPL bridge exploit drains ~200,000 XRP via relayer flaw

Security researchers say the Coreum-XRPL bridge lost 199,916.3 XRP on Aug. 9 after an attacker abused a relayer transaction-verification logic flaw. XRP withdrawals began from a pool that held about 200,410 XRP and fell to roughly 493.5 XRP, with 94 bridge payments completed in about 97 minutes. Coreum-XRPL uses a 17-of-28 multisig relayer approval model, and the unusual part is that withdrawals appear to have been properly authorized. Each payout carried the bridge multisig approval, and there is currently no evidence that validator or multisig keys were stolen. The breach came from “phantom deposits.” Relayers are supposed to detect qualifying deposits on the connected chain, but a flaw in how the bridge determined what counted as a deposit allowed attacker-controlled transactions (including the expected memo format tied to the bridge-issued wrapped CORE asset) to be treated as valid deposits. Once enough relayers signed off on the same fake deposit, the attacker generated unbacked bridge balances equivalent to about 200,001 XRP and then withdrew through the normal process. For traders: the Coreum-XRPL bridge exploit is a reminder that strong multisig custody does not fully remove cross-chain risk if relayer verification assumptions are wrong. Expect near-term caution toward bridged/LP exposures, while broader XRP price impact is likely limited unless more bridges show similar failures.
Neutral
The event is highly negative for the affected bridge’s trust, but the reported vulnerability is operational/verification-layer related (relayer deposit checks), not an XRP protocol-wide weakness. There is no evidence of stolen XRP keys, and withdrawals were still authorized via existing multisig approvals—suggesting the market impact on XRP price may be limited. In the short term, traders may reduce exposure to bridged assets and demand more scrutiny of cross-chain relayer mechanisms; in the long term, this could increase risk premiums for bridges and push projects toward stronger on-chain proofs or redesigned deposit verification.