The tx project team has provided insights into a cyber attack that targeted their cross-chain bridge connecting the XRP Ledger with their blockchain, resulting in a theft of $200,000.
An update on the XRPL bridge incident.
On August 9, the tx XRPL bridge was exploited and XRP was drained from the bridge's reserve wallet on the XRP Ledger. The bridge has been halted, the vulnerability has been identified, and all potential remedies are being evaluated. This…
— tx (@txEcosystem) August 11, 2026
The breach occurred on August 9, when the attacker exploited a flaw in the deposit processing logic. The bridge mistakenly accepted transactions without XRP as legitimate deposits, allowing the system to issue "wrapped" tokens on the tx network, which the hacker then used to withdraw actual coins from the reserve.
Developers emphasized that the attack did not affect funds in the mainnet or on centralized and decentralized exchanges.
According to xrpl.to, the withdrawal process lasted 97 minutes, during which nearly 200,000 XRP (valued at $199,916) was transferred in 94 transactions to two new wallets. Following these transactions, only 493.5 XRP remained in the reserve, down from approximately 200,410. Each transaction received confirmation from 17 out of 28 relay keys, which was the required amount according to the protocol.
Source: xrpl.to.Analysts pointed out that the cybercriminal did not gain access to private keys, and the XRP Ledger continued to function without disruptions.
Upon discovering suspicious activity, the tx team halted the bridge, patched the vulnerable code, enlisted blockchain experts, and reported all transaction data to the FBI’s Internet Crime Complaint Center. The developers are currently exploring options for compensating affected users.
Harmony Hack
In a related incident, the L1 blockchain Harmony also fell victim to a cyber attack. The project team announced that they are collaborating with exchanges to freeze the stolen funds and are considering network rollback options.
We are working with our team and appropriate exchanges to stop and freeze the funds.
We are working on a patch and rollback options.
Will update when we have new information. https://t.co/XB0nCwTAyN
— Harmony 💙 (@harmonyprotocol) August 12, 2026
An analyst using the pseudonym Juiceberg reported that the attacker generated 4 billion ONE tokens through empty blocks, representing 26% of the total token supply. Of these, 2.8 billion were transferred to exchanges.
Following this incident, the token's price plummeted nearly 30%.
Source: CoinGecko.Notably, in June 2022, Harmony had previously fallen victim to cybercriminals, losing $100 million. CertiK experts indicated that the attacker had somehow gained control over the platform's multi-signature wallet.
Analysts at Elliptic suggested that the hack was orchestrated by North Korean hackers, a conclusion later echoed by the FBI.
Additionally, on August 10, an unknown entity attacked the Coinsbuy platform, stealing $8 million. Just days prior, cybercriminals drained Lightning nodes through a vulnerability in BTCPay.
