XRP Bridge Drained After Software Treats Fake Deposits as Real

A flaw that went undetected during multiple audits allowed an attacker to create unbacked balances and withdraw XRP from the bridge’s reserves.

XRP Bridge Drained After Software Treats Fake Deposits as Real

A critical vulnerability in an XRP bridge protocol has resulted in the complete draining of its reserves after an attacker exploited a flaw that allowed fake deposits to be recognized as legitimate. According to Decrypt, the software incorrectly validated fabricated deposit transactions, enabling the malicious actor to generate unbacked balances and subsequently withdraw real XRP from the bridge's holdings. The full extent of the financial losses has not yet been publicly confirmed, though the bridge's reserves were reported to be fully depleted.

The vulnerability reportedly went undetected through multiple rounds of security audits, raising immediate questions about the thoroughness of the review process. Bridge protocols, which allow assets to move between different blockchain networks, have historically been high-value targets for attackers. Since 2022, cross-chain bridges have collectively lost billions of dollars to exploits, making them one of the most vulnerable categories of infrastructure in decentralized finance.

The incident adds further scrutiny to the reliability of smart contract auditing firms and the broader security standards applied to cross-chain infrastructure. For the XRP ecosystem specifically, the breach may dampen confidence among developers and institutional participants looking to build or utilize interoperability solutions on the network.

Investigators and the development team are expected to release a formal post-mortem detailing how the flaw originated and survived repeated audits. Affected users and the broader community will be monitoring whether any recovery or compensation mechanism will be established.

Source: Decrypt

Read original article ↗