Coreum cross-chain bridge exploit drains ~200,000 XRP
The Coreum cross-chain bridge exploit emptied nearly all funds on the XRPL side. On August 9, attackers drained 199,916 XRP from the Coreum bridge in about 97 minutes, via 94 multisig-authorized transactions.
Key details: the attack did not compromise XRPL private keys and did not break XRPL itself. Instead, the Coreum cross-chain bridge exploit exploited a flaw in the bridge’s relayer-based deposit verification logic. Fake deposit actions were accepted as valid, which then triggered real XRP withdrawals from the bridge’s XRP Ledger (XRPL) wallet.
Bridge impact: the bridge balance fell from roughly 200,410 XRP to 493.5 XRP. The compromised relayer process required 17 of 28 relayer keys to sign off, enabling the attacker to rapidly get the system to approve illegitimate payments.
Status and context: as of August 11, the bridge remained suspended. The Coreum Development Foundation had not yet published an official incident report. Coreum launched the bridge on March 20, 2024, aiming to connect XRPL with 110+ IBC-compatible chains, positioning itself as an XRP gateway to DeFi across broader ecosystems.
Security takeaway: because the design relies on relayers to attest deposits (rather than on-chain cryptographic proofs), a logic bug can collapse the trust model end-to-end. While this appears to be a third-party infrastructure failure—not an XRPL protocol-level vulnerability—the scale of the Coreum cross-chain bridge exploit raises scrutiny for cross-chain verification mechanisms.
Bearish
Expected near-term sentiment is bearish for XRP-linked infrastructure because the Coreum cross-chain bridge exploit shows how quickly large value can be drained when relayer-based deposit verification is flawed. Even though XRPL private keys weren’t compromised, the bridge’s near-empty state can trigger risk-off behavior: traders and liquidity providers may reduce exposure to affected bridge routes, and exchanges/DeFi frontends may slow integration until incident details are confirmed.
In the short run, this can increase volatility around XRP sentiment and any XRPL-bridge-related tokens/activities, as market participants typically treat major bridge hacks as “systemic smart-contract/infrastructure risk” rather than isolated incidents. Historically, similar bridge failures (e.g., when cross-chain relayers or message verification logic breaks) often lead to temporary liquidity fragmentation, higher spreads, and a brief sell-the-news effect followed by cautious stabilization once funds movement and root cause are understood.
Long-term, the impact depends on remediation: if Coreum publishes a credible incident report and upgrades verification to reduce relayer trust (or adds stricter on-chain validation), the market may partially recover. If not, the event can reinforce a discount on cross-chain utility and raise the required safety premium for routes that rely heavily on relayers.