The bridge between the TX Chain and XRP Ledger (XRPL) was exploited due to a bug in the XRPL relayer logic combined with the XRPL DefaultRipple feature.
The attacker constructed cross-currency XRPL payments that, due to DefaultRipple, were detected by our relayer as incoming bridge transfers even though the payments were sent to different XRPL addresses rather than the bridge vault. Due to insufficient destination validation in the relayer, these payments were incorrectly accepted as valid deposits, causing the bridge to mint corresponding assets on the TX Chain without receiving the required backing assets on XRPL.
The attacker subsequently extracted the entire unauthorized XRP supply from the TX Chain. 198,715.88 XRP was stolen in total. The other bridged assets were not materially affected and remain fully backed.
The stolen XRP was subsequently converted to ETH, bridged to Ethereum through THORChain, and the entire amount was ultimately transferred to Tornado Cash, after which direct tracing of the funds became significantly more difficult.
An update on the XRPL bridge incident.
On August 9, the tx XRPL bridge was exploited and XRP was drained from the bridge's reserve wallet on the XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. This was an isolated incident and future transactions will not be impacted. Here is what happened and what we are doing about it.
What happened
The attacker exploited the bridge's deposit-detection logic. The bridge's software incorrectly registered transactions that never actually delivered any XRP to the bridge as deposits, and minted bridged XRP on the tx chain against them. The attacker then withdrew real XRP from the reserve against those unbacked balances. This bridge had undergone multiple internal and third-party audits prior to deployment and the attacker exploited a previously unidentified vulnerability.
Impact
The exploit is isolated to a single asset: bridged XRP on the tx chain, which is not currently fully backed. All other bridged assets remain fully backed. All other tokens, including funds held onchain, on centralized exchanges, and in DEXs, are unaffected.
Actions taken
• Halted the XRPL <> tx bridge.
• Identified and remedied the audited code that made the exploit possible.
• Traced the movement of the stolen funds across chains.
• Filed a formal complaint with the FBI's Internet Crime Complaint Center, including complete transaction records and additional identifying information.
• Engaged with blockchain forensics specialists and are coordinating with our security partners on the investigation.
Making this right
As we pursue all legal paths forward, we are simultaneously evaluating all options for remedying the situation for affected users.
The mechanism and timeline will be shared in a further update.
Next steps
tx intends to pursue identification and prosecution of the attacker to the fullest extent of the law. The bridge remains halted while we review and strengthen its security.
No action is currently required from holders. Be cautious of any account or site claiming to offer recovery of bridged XRP or other tokens; official updates will only come from tx channels.