A cross-chain bridge linking Coreum and the XRP Ledger was exploited for approximately 200,000 XRP, according to reports published Tuesday. The attack targeted a weakness in the bridge's relayer system, the component responsible for verifying and passing transaction data between the two networks.
Reports indicate the exploit unfolded quickly. One outlet described attackers draining 99.7% of the bridge's reserves in under two hours. That pace suggests the vulnerability was either identified in advance or exploited through an automated process once discovered.
Cross-chain bridges connect otherwise separate blockchains, letting users move assets like XRP between ecosystems that do not natively communicate. Coreum, a network built to interoperate with the XRP Ledger, relies on such a bridge to let XRP holders access its smart contract and tokenization features.
Relayers are a common point of failure in bridge architecture. They act as intermediaries, confirming that a deposit on one chain corresponds to a legitimate mint or release on the other. If a relayer's verification logic contains a flaw, attackers can potentially forge or manipulate confirmations to withdraw funds without a matching deposit.
Bridge exploits have been among the costliest categories of attack across the broader crypto industry in recent years. Because bridges typically hold large pools of locked assets to back tokens minted on connected chains, they present concentrated targets for attackers who find a way to bypass their security checks.
Neither report detailed the exact technical mechanism behind the relayer flaw, nor whether the exploited funds have been recovered or frozen. The current status of the Coreum-XRPL bridge, including whether it has been paused for review, was not specified in available reporting.
The incident adds to a long list of bridge-related security failures that have prompted developers across the industry to rethink how cross-chain verification is designed. Projects have increasingly moved toward multi-party validation, time-locked withdrawals, and independent audits to reduce reliance on any single relayer or verification path.
Market Impact
An exploit of this size represents a meaningful loss for a bridge of Coreum's scale, though it is unlikely to move broader XRP or XRP Ledger markets given the token's overall liquidity. The more immediate impact is likely to fall on Coreum's ecosystem, where confidence in the bridge's security and its ability to support cross-chain XRP transfers may be affected.
For the wider industry, the exploit reinforces ongoing scrutiny of bridge infrastructure as a persistent weak point in decentralized finance. Projects operating similar relayer-based bridges may face renewed pressure to audit their systems following this incident.
The exploit underscores the continued security risks tied to cross-chain bridges, even as they remain essential infrastructure for moving assets like XRP between blockchains.
Frequently Asked Questions
What happened to the Coreum-XRPL bridge?
Reports indicate attackers exploited a flaw in the bridge's relayer system, draining approximately 200,000 XRP from its reserves.
What is a relayer in a cross-chain bridge?
A relayer verifies transactions on one blockchain and communicates that information to a connected chain, allowing assets to move between the two networks.
How much of the bridge's reserves were affected?
One report stated that 99.7% of the bridge's reserves were drained, occurring within less than two hours.
Has the exploited XRP been recovered?
Available reporting does not confirm whether the funds have been recovered or whether the bridge has been paused for review.