An XRP bridge lost nearly 200,000 XRP, worth about $200,000 at current prices, after a software flaw let an attacker claim deposits that were never made, then withdraw real tokens against the fake balances.
The bridge connected the XRP Ledger to Coreum, a separate blockchain which rebranded this March as tx, a U.S.-based outfit focused on tokenizing real-world assets. The tokens XRP left the bridge's reserve wallet in 97 minutes on Aug. 9 before the system was halted.
A bridge is supposed to work like a vault with a receipt system. A user sends XRP into a reserve wallet on the XRP Ledger, and the bridge creates an equivalent amount of bridged XRP on the other chain. Returning those tokens lets the user withdraw the real XRP held in the reserve.
The attacker found a way to make that system issue the receipts without putting anything into the vault.
According to tx, the bridge's software registered transactions as deposits even though they never delivered XRP to the bridge. That gave the attacker bridged XRP on the tx chain without the real XRP that was supposed to back it. Those unbacked tokens then went back through the bridge, and the attacker withdrew real XRP from the reserve.
The drain began at 19:16 UTC. Each payout was authorized by 17 of the bridge's 28 relayers, a majority signing off exactly as designed, because the bridge's own records told them the deposits were real.
Relayers are programs that watch both blockchains and approve transfers when the bridge's records say a withdrawal is owed.
The specific failure sat one layer down, however, as the relayer code processed payments carrying the bridge's memo without first verifying the destination address.
tx confirmed the deposit-detection flaw in an update, saying the attacker exploited software that incorrectly recognized transactions that delivered no XRP to the reserve.
An update on the XRPL bridge incident.On August 9, the tx XRPL bridge was exploited and XRP was drained from the bridge's reserve wallet on the XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. This…
The project added it has identified and fixed the vulnerable code, engaged blockchain forensics specialists and filed a complaint with the FBI's Internet Crime Complaint Center. It has not said how affected holders will be made whole.
Meanwhile, the stolen XRP did not stay put. Onchain tracking shows most of it moved onward within hours through several other addresses.
Source
This article is syndicated for educational reading. For the latest updates, visit the original publisher.
Read on coindesk.com