A deposit verification error in the Coreum cross-chain bridge led to the outflow of 199,916 XRP. The attacker was able to withdraw reserves by making the system recognize a normal deposit without actually sending any XRP. The attack occurred on August 9, with losses exceeding $200,000. Withdrawals were made in 94 transactions, each bearing multiple signatures. A verification error in the relayer software has been identified as the cause of the incident. The software monitored payments that included Coreum recipient memos but failed to verify the actual destination. As a result, the attacker was able to withdraw real XRP stored in the bridge liquidity account. TX had conducted internal audits and third-party audits before the bridge deployment, but verification errors remained. Following the incident, only 493 XRP remained in the bridge liquidity account. TX has now acknowledged that the bridge XRP is not fully collateralized. This incident specifically illustrates the attack method used in the Coreum bridge leak.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























