Intelligence Brief
A bridge connecting the XRP Ledger with the tx blockchain was drained of nearly 200,000 XRP after its software reportedly accepted nonexistent deposits as valid.
The attacker generated unbacked representations of XRP on the destination network and then exchanged those assets for genuine XRP held in the bridge’s reserve wallet. The failure did not require the attacker to compromise the relayers’ signing keys. The relayers reportedly authorised withdrawals using incorrect deposit records produced by the bridge software.
The operator halted the bridge, applied a patch and filed a complaint with the US Federal Bureau of Investigation, according to CoinDesk. The amount recovered, if any, and the plan for compensating affected users have not been disclosed.
The bridge operator’s technical post-mortem and an independent audit are still needed to confirm the full failure path.
An update on the XRPL bridge incident.
On August 9, the tx XRPL bridge was exploited and XRP was drained from the bridge’s reserve wallet on the XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. This…
— tx (@txEcosystem) August 11, 2026
Strategic Assessment
The incident exposes a verification-layer weakness. Multisignature relayers provide little protection when every signer relies on the same faulty record of whether collateral entered the system.
Users who held genuine XRP in the reserve effectively carried the risk created by unbacked assets on the connected chain. Bridge operators and auditors must therefore verify the source-chain event itself rather than trust a local database entry or incomplete deposit parser.
The loss is limited compared with larger bridge attacks, but the mechanism has wider relevance. Any bridge using similar deposit-recognition logic could issue assets without corresponding collateral.