Disclaimer: The opinions expressed by our writers are their own and do not represent the views of U.Today. The financial and market information provided on U.Today is intended for informational purposes only. U.Today is not liable for any financial losses incurred while trading cryptocurrencies. Conduct your own research by contacting financial experts before making any investment decisions. We believe that all content is accurate as of the date of publication, but certain offers mentioned may no longer be available.
U.S.-based RWA platform tx, known for its Sologenic and Coreum projects, has broken its silence and published the official findings of its investigation into the hack of its cross-chain bridge. The attack, which occurred on Aug. 9, lasted just 97 minutes and cost the ecosystem 200,000 XRP.
The main takeaway is that the attacker did not compromise any cryptographic keys but instead exploited a critical flaw in the bridge's deposit verification logic.
The illusion in the memo
Initial theories circulating within specialized communities linked the incident to a malfunction of the "rippling" feature on the XRP Ledger. However, on-chain analysis by xrpl.to and tx's official report disproved this hypothesis: the vulnerability existed exclusively within the bridge software.
The hacker simulated deposits by transferring their own wrapped CORE tokens between addresses under their control and attaching text memos containing destination details for the Coreum network. Validators read the information from the memo, but because the code lacked a recipient verification mechanism, the system did not check whether the funds had actually been sent to the bridge's wallet.

As a result, the bridge issued unbacked tokens, while a quorum of 17 multisignature keys held by relay nodes automatically approved their withdrawal, transferring real XRP from the reserve to the attacker's address.
Hunting the hacker
As of Aug. 12, tx developers have completely halted bridge operations while dealing with the consequences of the incident, and the verification bug has already been fixed.
The company emphasized that the bridge's smart contracts had previously undergone several rounds of internal and independent audits, none of which identified the flaw.
The official report outlines two key areas of its ongoing work:
- Containing the damage. The team has fully isolated the risk, but bridged XRP within the tx network temporarily lost its full backing. The platform's native tokens and funds held on decentralized and centralized exchanges were not affected.
- Involving the FBI. The tx team traced the stolen funds through a chain of intermediary addresses and filed an official complaint with the FBI's Internet Crime Complaint Center (IC3).
The platform is now developing a compensation mechanism and timeline for affected users. Developers clarified that asset holders do not need to take any action and urged them to ignore unofficial "token recovery" services amid increased scam activity.



U.Today Editorial Team
Dan Burgin