On August 9, an attacker exploited a validation gap in the Coreum bridge's relayer software, successfully draining approximately 200,000 XRP tokens in a span of just 97 minutes. Coreum developers immediately halted bridge operations to prevent further losses and secure the remaining assets. Crucially, the exploit was isolated to the relayer middleware and does not represent a structural weakness or vulnerability in the underlying XRP Ledger (XRPL) protocol itself.
The incident comes at a sensitive time for XRP, which has been attempting to solidify its position above key psychological benchmarks following recent legal clarifications in the US. The breach of the $1 support level reflects heightened market caution regarding cross-chain interoperability risks. While the total value stolen is relatively modest compared to historical DeFi exploits, the breach of trust in third-party infrastructure often leads to immediate localized sell pressure.
From a regulatory perspective, this event highlights the ongoing scrutiny of bridge security by US authorities, as cross-chain protocols remain a primary target for illicit activity and systemic risk. Investors should monitor Coreum’s upcoming post-mortem report and the official restoration of bridge services. In the immediate term, XRP traders should watch for a reclaim of the $1 level; failure to hold this support could invite further downside volatility as the market digests the security implications.