Mark RadarMARK RADAR
About
EN
Sign in

XRP Bridge Loses $200,000 After Software Flaw Enables Fake Deposits

1 reports · First detected 2026-08-12 · Last active 2026-08-12

Cross-chain bridges allow users to move assets between otherwise separate blockchains, but their security depends heavily on accurately verifying deposits and maintaining sufficient reserves. A bridge linking the XRP Ledger with Coreum, now known as tx, exposed that vulnerability when its software treated fabricated deposits as genuine, allowing an attacker to draw assets from the service’s reserve pool.

The operator disclosed in August 2026 that the attacker exploited the flaw to withdraw about 200,000 XRP, resulting in losses valued at roughly $200,000. The bridge was suspended on an emergency basis and the software vulnerability has since been patched. The operator also retained blockchain forensics specialists to trace the funds and investigate the breach, while formally reporting the case to the US Federal Bureau of Investigation.

All Coverage

1 original reports

The Backstory

The history behind this event
Allbridge Halts Protocol After $1.65 Million Flash-Loan Exploit2026-07-20 · 4 reports · similarity 0.81

Allbridge Core is a cross-chain bridge designed to move stablecoins between blockchains including Solana and Ethereum. Such protocols pool liquidity and coordinate transfers across otherwise separate networks, making them important infrastructure for decentralized finance. Their concentration of assets and reliance on smart-contract pricing also make them frequent targets, with any failure potentially exposing liquidity providers and disrupting users’ ability to move funds between chains.

On July 19, an attacker borrowed $1.12 million through a flash loan from Solana-based lending protocol Kamino and rapidly swapped USDC for USDT to distort Allbridge Core’s pool ratios, according to Onchain Lens. The maneuver enabled withdrawals at favorable rates and drained about $1.65 million. Allbridge paused the protocol and urged users to remove liquidity from affected pools. PeckShield and CertiK said the stolen assets were later bridged from Solana to Ethereum and deposited into privacy pools.

Axelar Cross-Chain Bridge Exploit Drains $4.67 Million2026-06-22 · 2 reports · similarity 0.81

Cross-chain bridges lock assets on one blockchain and mint corresponding tokens on another. If their validation systems fail, unbacked tokens can be redeemed for real assets. The IBC bridge between Axelar Network and Secret Network had operated since early 2023. The incident underscores how bridge contracts and monitoring systems remain critical risks in the cross-chain ecosystem.

On June 10, 2026, an attacker exploited an “infinite mint” vulnerability in the Secret-side ics20-for-axelar contract, which failed to verify the source channel. The attacker minted seven types of unbacked tokens and redeemed them for about $4.67 million in assets. The incident did not come to light until June 17. Axelar subsequently disconnected Secret Network and notified law enforcement, while some of the funds flowed to Ethereum, BNB Chain and exchanges.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)