Coreum’s cross-chain bridge lost 200,000 XRP because relayers failed to verify whether deposited assets reached the correct bridge wallet address. Attackers created fake deposits using wrappe
- Coreum’s cross-chain bridge lost 200,000 XRP because relayers failed to verify whether deposited assets reached the correct bridge wallet address.
- Attackers created fake deposits using wrapped CORE transfers, allowing Coreum validators to authorize genuine XRP withdrawals through its multisignature system successfully.
- Coreum suspended its bridge while investigators tracked stolen XRP across intermediary wallets, placing greater scrutiny on TX’s cross-chain security controls.
Coreum’s cross-chain bridge lost approximately 200,000 XRP because its relayers failed to properly verify transactions submitted as deposits. According to an analysis from xrpl.to, the attacker exploited Coreum’s verification system rather than any vulnerability within the XRP Ledger.
The exploit lasted about 97 minutes and allowed the attacker to create deposits that appeared legitimate to Coreum’s relayers. Initial social media speculation linked the incident to the XRP Ledger’s rippling function, raising concerns about the network’s transaction mechanics.
However, xrpl.to rejected that explanation because native XRP does not have an issuer or require trust lines. Consequently, the analysis identified Coreum’s cross-chain verification process as the central weakness behind the loss.
Investigators also found that the attacker did not compromise the private keys controlling the bridge’s multisignature wallet. Instead, Coreum’s own validators authorized the transactions that transferred genuine XRP from the bridge to the attacker. Each malicious payment received approval from 17 of the bridge’s 28 relayer keys, meeting its required multisignature threshold.
Also Read: Zama expands ZAMA access across Europe through Revolut listing
Coreum Relayers Missed a Critical Recipient Check
According to xrpl.to, the attacker transferred wrapped CORE tokens between separate XRP Ledger wallets under their own control. Those transactions contained memos with transfer details that Coreum’s relayers used when processing deposits into its network.
Because Coreum’s bridge issued the wrapped tokens, their movements appeared within the bridge’s XRP Ledger transaction history. However, the relayer system reportedly failed to verify whether those assets actually reached the bridge’s designated deposit address.
That omission allowed transfers between attacker-controlled wallets to appear as legitimate deposits when Coreum processed their accompanying memos. Consequently, the bridge credited the attacker with balances on Coreum despite receiving no corresponding assets from those transactions.
The attacker subsequently requested withdrawals against those balances, turning the fabricated deposits into genuine XRP transfers from Coreum’s reserves. Moreover, validators approved those withdrawals via the bridge’s standard multisignature process rather than using stolen or compromised signing keys.
Around 200,000 XRP eventually left the bridge’s wallet as the attacker repeatedly exploited the same verification weakness. The findings therefore separate the exploit from XRP Ledger security and place responsibility on Coreum’s bridge implementation.
Exploit Raises Questions Over TX’s Cross-Chain Controls
The security incident also places scrutiny on TX, the company connected with Coreum and the broader Sologenic ecosystem. Its development history began with Sologenic on the XRP Ledger before expanding through the separate Coreum Layer 1 blockchain.
Coreum and Sologenic later merged their ecosystems under the United States-based TX brand in March 2026. TX has positioned its infrastructure around real-world asset tokenization, making reliable cross-chain verification an important part of its institutional strategy.
However, the reported failure involved a basic recipient verification step within infrastructure responsible for protecting bridge reserves. TX had not published an official post-mortem explaining the incident at the time covered by the available analysis.
Meanwhile, the Coreum bridge remained suspended while investigators tracked transactions connected with the stolen XRP. On-chain trackers observed the funds moving through several intermediary wallets created approximately six weeks before the attack. Additionally, the attacker’s identity remained unknown as the XRP moved across addresses potentially designed to complicate transaction tracing.
Conclusion
Available transaction evidence points toward Coreum’s bridge verification logic rather than an underlying XRP Ledger vulnerability. The exploit ultimately turned fabricated deposits into authorized withdrawals because relayers failed to confirm where the original assets were sent.
Also Read: XRP Prints New 2026 Low as Analyst Flags $1 Support Sweep as Key Setup
The post Coreum Bridge Loses 200,000 XRP as Analysis Exposes Critical Verification Failure appeared first on 36Crypto.