Coreum Cross-Chain Bridge Exploit Drains 200,000 XRP; Token Slides Below $1
Nearly 200,000 XRP tokens were drained from the Coreum cross-chain bridge on August 9 in a 97-minute exploit targeting relayer software validation logic. The incident pushed XRP below $1 for the first time since 2024 and forced the bridge to halt operations.
Coreum Cross-Chain Bridge Exploit Drains 200,000 XRP; Token Slides Below $1
Ninety-seven minutes. That's all it took for an attacker to drain nearly 200,000 XRP from the Coreum cross-chain bridge on August 9, pushing XRP below the $1 psychological threshold for the first time since 2024.
The exploit targeted a validation gap in the bridge's relayer software, the off-chain component responsible for verifying and passing messages between chains. The XRP Ledger itself was not compromised. That distinction matters technically, but it did little to cushion the market reaction: XRP fell 5.2% over 24 hours to $0.99 as the incident spread across trading desks.
Coreum halted bridge operations following the attack. On the surface, that's a point in favor of the team's incident response. A functioning kill switch is not nothing. But the halt also means cross-chain liquidity routed through Coreum is frozen, and there's no public timeline for resumption. Bridges that go dark after an exploit have a poor track record of recovering user confidence quickly, even when the underlying protocol is intact.
The mechanics here fit a pattern that security researchers have flagged for years: attackers are no longer primarily hunting for flaws in smart contract code or base-layer consensus. They're targeting the operational layer around bridges, specifically the relayer infrastructure that most users never think about. Relayers are trusted intermediaries. When their validation logic fails to properly verify state transitions or message authenticity, an attacker can push through fraudulent withdrawals without touching the underlying chain at all.
An attacker drained nearly 200,000 XRP tokens from the Coreum bridge in 97 minutes on August 9, exploiting a validation gap in the relayer software rather than any weakness in the XRP Ledger.
That framing is important for XRP holders: the ledger is clean. The bridge is a separate product built on top of it. Still, perception rarely tracks technical nuance in real time, and XRP crossing back below $1 will sting for a holder base that watched the token spend much of 2024 and 2025 above that level.
In dollar terms, 200,000 XRP at current prices represents roughly $198,000 in losses. That's a rounding error compared to the Ronin bridge hack in March 2022 ($625 million), the Poly Network exploit in August 2021 ($611 million), or the Nomad bridge collapse in August 2022 ($190 million). But scale isn't the only metric that matters. Each successive bridge exploit adds to a cumulative credibility problem for the entire cross-chain infrastructure category. Institutions and retail users alike are keeping score.
Cross-chain bridges remain genuinely necessary infrastructure. Multi-chain liquidity doesn't move without them. The total value locked across bridge protocols still runs into the billions, and demand for interoperability isn't going away. What this incident reinforces is that the security investment flowing into base-layer protocols has not kept pace with the operational complexity of the relayer and validation layers wrapping them. Auditing a smart contract is now table stakes. Auditing the full relayer stack, including message validation logic under adversarial conditions, is where the gaps remain.
The Coreum exploit is small by historical standards but precise in its targeting. Attackers found a seam in the validation logic, moved fast, and were out in under two hours. That efficiency is a signal. Bridge operators still running relayer software without formal verification of their validation logic should treat August 9 as a deadline, not a data point.






