XRP Falls Below $1 for First Time Since 2024 After Coreum Bridge Hack

An attacker needed less than an hour and a half to talk twenty-one independent relayers into believing something that wasn’t true, and XRP spent the next two days paying for it.
On August 9, an attacker exploited a flaw in the deposit verification software behind Coreum’s cross-chain bridge on the XRP Ledger, tricking the bridge into treating fake deposits as genuine and draining 199,916 XRP, roughly $200,000, in just 97 minutes. All twenty-one of the bridge’s independent relayers were fooled by the same trick simultaneously, a detail that says more about a shared software flaw than about any individual relayer’s judgment. Bridge operators halted operations once the exploit was identified.
The XRP Ledger itself was never touched, this was a flaw in Coreum’s bridge software specifically, and Ripple Labs was not involved in or compromised by the incident. That distinction didn’t stop the broader market reaction: two days later, XRP briefly touched $0.99, its first dip below $1 since November 2024.
A $200,000 exploit is small by the standards of this year’s larger hacks, but the mechanism, all relayers independently verifying and all independently getting fooled, is the more concerning part. Cross-chain bridges concentrate exactly this kind of shared trust assumption, and a flaw in the verification logic itself defeats redundancy that would normally catch a single bad actor.
Want to understand how cross-chain bridges actually work and why they’re a common attack target? Learn more in the Bitcoin Academy.
