Tx said an attacker drained nearly 200,000 XRP, worth about $202,000, from its XRP Ledger bridge on August 9 by exploiting a flaw in the software that detects deposits.

In a post on X on Tuesday, the team behind the bridge linking Tx Chain and the XRP Ledger said the bug caused the system to record certain transactions as XRP deposits even though no XRP had actually arrived at the bridge.
How the bridge was exploited
“The attacker exploited the bridge's deposit-detection logic,” Tx wrote. “The bridge's software incorrectly registered transactions that never actually delivered any XRP to the bridge as deposits, and minted bridged XRP on the tx chain against them.”
Tx said the attacker used those false deposits to create unbacked XRP on Tx Chain, then sent it back through the bridge in exchange for real XRP.
The project describes Tx as a layer-1 blockchain ecosystem launched in March through the combination of the Coreum blockchain and Sologenic, an XRP Ledger-based tokenization and trading platform.
According to the company, the bridge had gone through multiple internal and third-party audits before deployment, but the issue was not caught.
XRPL tracked 94 payments over 97 minutes
XRPL, an independent XRP Ledger trading and analytics platform, said the bridge released about 199,916 XRP through 94 payments over 97 minutes.
Each of those payments was approved by 17 of the bridge’s 28 relayers, the programs that watch both blockchains and authorize transfers.
XRPL said the relayers treated the attacker’s self-directed transactions as deposits. Once those balances were credited, the attacker withdrew the resulting unbacked XRP through the bridge’s normal process.

XRPL rejects the “rippling” explanation
XRPL also disputed an early claim that the funds had been drained through “rippling,” a feature on the XRP Ledger that moves issued tokens across trust lines. Native XRP cannot move through rippling, the platform said.
“A widely-shared warning blamed ‘rippling’ and an on-by-default account flag. The ledger says otherwise: every one of those payments was signed by the bridge’s own multisig, and native XRP cannot be rippled at all,” XRPL wrote. “Reading both public chains together, the real cause is a relayer that mistook the attacker’s own self-payments for deposits.”
Stolen funds were moved to Ethereum and Tornado Cash
In a separate post on X, Reza Bashash, a principal at CoreNest Capital and co-founder of Sologenic and Coreum, said the attacker converted the stolen XRP into Ethereum, moved the funds onto the Ethereum network through THORChain, and sent the full amount to crypto mixer Tornado Cash, making the trail much harder to follow.
Bridge remains offline
Tx said it halted the bridge, patched the affected code, traced the stolen funds, and filed a complaint with the FBI’s Internet Crime Complaint Center. The company also said it hired blockchain forensics specialists and is working with security partners.
“As we pursue all legal paths forward, we are simultaneously evaluating all options for remedying the situation for affected users,” Tx said.
The bridge is still offline while the team reviews its security. Tx said holders do not need to take any action and warned users to avoid accounts or websites claiming they can recover the missing funds.
XRP price shows limited reaction
Decrypt reported that XRP has shown little immediate price reaction. The Ripple-linked token was still hovering around the $1 level, with a market capitalization of roughly $64 billion, and was down about 5.5% over the last 30 days.
On Myriad, the prediction market built by Decrypt’s parent company, traders currently expect XRP to remain around the $1 price point for the rest of the week.

