According to tx, the bridge’s software registered transactions as deposits even though they never delivered XRP to the bridge. That gave the attacker bridged XRP on the tx chain without the real XRP that was supposed to back it. Those unbacked tokens then went back through the bridge, and the attacker withdrew real XRP from the reserve.
The drain began at 19:16 UTC. Each payout was authorized by 17 of the bridge’s 28 relayers, a majority signing off exactly as designed, because the bridge’s own records told them the deposits were real.
Relayers are programs that watch both blockchains and approve transfers when the bridge’s records say a withdrawal is owed.
The specific failure sat one layer down, however, as the relayer code processed payments carrying the bridge’s memo without first verifying the destination address.
tx confirmed the deposit-detection flaw in an update, saying the attacker exploited software that incorrectly recognized transactions that delivered no XRP to the reserve.
An update on the XRPL bridge incident.
On August 9, the tx XRPL bridge was exploited and XRP was drained from the bridge’s reserve wallet on the XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. This…
— tx (@txEcosystem) August 11, 2026
The project added it has identified and fixed the vulnerable code, engaged blockchain forensics specialists and filed a complaint with the FBI’s Internet Crime Complaint Center. It has not said how affected holders will be made whole.
Meanwhile, the stolen XRP did not stay put. Onchain tracking shows most of it moved onward within hours through several other addresses.


