News
Public · Published
How a Bridge Can Drain Without Stolen Keys: Inside the 200,000 XRP Relayer Logic Flaw
An attacker exploited a relayer logic flaw in the Coreum‑XRPL bridge and drained almost 200,000 XRP without needing validator or multisig keys.
Published:
Updated:
What happened
An attacker exploited a relayer logic flaw in the Coreum‑XRPL bridge and drained almost 200,000 XRP without needing validator or multisig keys.
Confirmed
Global impact / market context
The loss shows that bridge software bugs can cause large token drains even when private keys are safe, raising concerns about the security of cross‑chain infrastructure that many projects rely on.
Analyst inference
XRP’s price and liquidity—its ability to be quickly bought or sold—can be affected when large amounts are suddenly removed from a bridge, as traders may fear further technical issues and lose confidence in similar interoperability solutions.
Analyst inference
What to watch
- Updates from Coreum and XRPL teams on patches or audits that fix the relayer logic flaw, which could restore confidence and prevent further drains. Proposed
- Regulatory or industry guidance on bridge security standards, which may lead to stricter compliance requirements for cross‑chain projects. Proposed
- Any large XRP movements from other bridges or custodial services, indicating whether attackers are targeting similar vulnerabilities elsewhere. Proposed
Affected assets
- XRP — XRP