XRP Bridge Exploited for $200,000 via Fake Deposit Vulnerability
An attacker drained approximately $200,000 worth of XRP from a cross-chain bridge by exploiting a flaw that caused the bridge software to treat fabricated, unbacked XRP deposits as legitimate. The bridge has been halted following the incident and its operator has filed a complaint with the FBI.
A cross-chain bridge holding XRP reserves was exploited for roughly $200,000 after a software vulnerability allowed an attacker to create unbacked XRP tokens on a secondary blockchain and have them accepted as genuine deposits by the bridge.
The mechanics of the attack involved minting synthetic, uncollateralized XRP on another chain, depositing those tokens into the bridge, and then redeeming them for real XRP held in the bridge's reserve. The bridge software failed to distinguish between the fabricated tokens and legitimate deposits, enabling the attacker to drain real funds.
Following discovery of the exploit, the bridge operator halted all activity on the platform to prevent further losses. A formal complaint has been filed with the FBI, indicating law enforcement is now involved in the investigation.
- Approximately 200,000 XRP stolen from bridge reserves
- Attack vector: fake deposit accepted as real by bridge software
- Bridge operations halted post-exploit
- FBI complaint filed by the bridge operator
Key facts
- •Approximately $200,000 in XRP drained from a cross-chain bridge
- •Attacker created unbacked synthetic XRP on another blockchain and exchanged it for real XRP
- •Bridge software failed to validate deposit authenticity
- •Bridge has been halted following the exploit
- •Operator filed a complaint with the FBI