200,000 XRP Theft Update: TX Team Breaks Silence, Enlists FBI, Halts Flaws

fiverr
fiverr


U.S.-based RWA platform tx, known for its Sologenic and Coreum projects, has broken its silence and published the official findings of its investigation into the hack of its cross-chain bridge. The attack, which occurred on Aug. 9, lasted just 97 minutes and cost the ecosystem 200,000 XRP.

The main takeaway is that the attacker did not compromise any cryptographic keys but instead exploited a critical flaw in the bridge’s deposit verification logic.

The illusion in the memo

Initial theories circulating within specialized communities linked the incident to a malfunction of the “rippling” feature on the XRP Ledger. However, on-chain analysis by xrpl.to and tx’s official report disproved this hypothesis: the vulnerability existed exclusively within the bridge software.

itrust

Ripple Renews NYU Abu Dhabi Deal


Hyperliquid (HYPE), Ethereum (ETH), Bitcoin (BTC) and Shiba Inu (SHIB) Price Analysis for August 11: Market Finally Moves

You Might Also Like

Title news

The hacker simulated deposits by transferring their own wrapped CORE tokens between addresses under their control and attaching text memos containing destination details for the Coreum network. Validators read the information from the memo, but because the code lacked a recipient verification mechanism, the system did not check whether the funds had actually been sent to the bridge’s wallet.

Article image
Reza Bashash, a technical lead from tx, breaks down how 200,000 XRP theft occurred, Source: Reza Bashash via X

As a result, the bridge issued unbacked tokens, while a quorum of 17 multisignature keys held by relay nodes automatically approved their withdrawal, transferring real XRP from the reserve to the attacker’s address.

Hunting the hacker

As of Aug. 12, tx developers have completely halted bridge operations while dealing with the consequences of the incident, and the verification bug has already been fixed.

The company emphasized that the bridge’s smart contracts had previously undergone several rounds of internal and independent audits, none of which identified the flaw.

You Might Also Like

Title news

The official report outlines two key areas of its ongoing work:

  • Containing the damage. The team has fully isolated the risk, but bridged XRP within the tx network temporarily lost its full backing. The platform’s native tokens and funds held on decentralized and centralized exchanges were not affected.
  • Involving the FBI. The tx team traced the stolen funds through a chain of intermediary addresses and filed an official complaint with the FBI’s Internet Crime Complaint Center (IC3). 

The platform is now developing a compensation mechanism and timeline for affected users. Developers clarified that asset holders do not need to take any action and urged them to ignore unofficial “token recovery” services amid increased scam activity.



Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*