The Coreum cross-chain bridge lost 199,916 XRP, worth roughly $200,000, after attackers exploited a weakness in the relayer logic used to validate deposits between the XRP Ledger and Coreum. The August 9 attack targeted the bridge infrastructure rather than the XRP Ledger itself, prompting operators to halt the service and patch the affected verification process.
The distinction is critical because the exploit centered on how the bridge recognized incoming XRP. Coreum’s official developer documentation describes the XRPL-Coreum bridge as infrastructure connecting a Coreum smart contract with an XRP Ledger multisignature account through relayers. That additional verification layer became the attack surface even while the underlying XRP Ledger continued operating normally.
Crafted memos created deposits that never existed
The attacker executed 94 crafted transactions over roughly 97 minutes, using memo data designed to resemble legitimate bridge deposit references. The corresponding XRP, however, had not reached the bridge’s designated reserve address. The relayer accepted the memo information without independently confirming the expected destination, allowing transactions without matching reserve deposits to be treated as valid.
The attacker then moved the bridge’s wrapped Coreum token among controlled wallets while attaching memos that imitated legitimate deposit confirmations. Those transactions generated internal balances that appeared backed by XRP even though no corresponding assets had entered the reserve, creating what amounted to phantom deposits inside the bridge.
Those fabricated balances were subsequently converted into withdrawal requests. The bridge’s multisignature arrangement approved the transactions, releasing actual XRP from its reserves. Unbacked bridge credits were therefore transformed into withdrawals of genuinely custodied XRP, ultimately draining nearly 200,000 tokens.
Coreum’s own technical documentation shows why relayer validation is central to the system: XRPL-native assets are represented on Coreum after bridge processing, while relayers coordinate activity between the two networks. The exploit demonstrates how incorrect recognition of a source-chain payment can compromise the bridge’s accounting even without breaking either blockchain’s consensus rules.
Bridge shutdown puts verification controls under scrutiny
Operators halted the bridge after detecting the exploit and deployed a patch targeting the vulnerable verification logic. The immediate remediation focused on preventing memo information alone from establishing that an XRP deposit had reached the correct reserve destination.
The incident coincided with unusually heavy XRP market activity, including a brief move below $1, higher futures open interest and elevated spot volume. Larger wallets and exchange withdrawals also showed notable movements. Those developments occurred during the same period, but the available evidence does not establish that the Coreum exploit caused the broader XRP market activity.
The breach ultimately exposes a familiar structural risk in cross-chain systems. A blockchain may remain technically secure while software connecting it to another network introduces separate assumptions around custody, transaction recognition and message validation. For Coreum, restoring confidence now depends on proving that bridge deposits are independently verified before any corresponding balance can be credited or withdrawn.

