#What Happened to the Coreum Cross-Chain Bridge?
The Coreum cross-chain bridge, designed to connect with the XRP Ledger, suffered a major incident on August 9. Within a brief time span of less than two hours, the bridge lost approximately 199,916 XRP, causing its balance to plummet from around 200,410 XRP to a mere 493.5 XRP.
This attack did not result from a breach of the XRP Ledger or the compromise of any private keys. Instead, the attacker exploited a weakness in the bridge’s relayer logic that erroneously recognized fake deposit actions as legitimate. This security flaw allowed for unauthorized withdrawals of real XRP from the bridge’s wallet.
#How Did the Attack Function?
Understanding how cross-chain bridges work is crucial. These bridges hold assets on one blockchain and create equivalent tokens on another platform. The Coreum bridge employed a multisignature relayer system where multiple relayer nodes must authorize transactions. This setup was responsible for managing exchanges between the XRP Ledger and Coreum’s ecosystem.
The vulnerability occurred within the deposit verification process. The relayer protocol was initially intended to verify that deposits on one chain were authentic before allowing withdrawals on another. However, the attacker managed to generate fake deposit actions that the system mistakenly accepted. This deception led to genuine XRP withdrawals from the bridge’s XRPL wallet.
An analysis of the on-chain transactions reveals that 94 multisig-authorized payments were executed in a swift 97-minute window, from 19:16 to 20:53 UTC. The exploitation required the signature of 17 out of 28 relayer keys, successfully tricking the consensus mechanism into approving a large number of illegitimate transactions within a rapid timeframe.
A sharper way to see the markets in just 5 minutes.
Same news, different lens. We cut through the noise and hand you the overlooked ideas and the deeper read the crowd misses. Join 38,000+ investors seeing the markets differently.
#What is the Current Status of the Bridge?
As of August 11, the Coreum bridge has been suspended. The Coreum Development Foundation has yet to provide an official report on the incident, leaving community members to examine on-chain data and conduct independent analyses to grasp the situation.
The bridge initially launched on March 20, 2024, with the intention of linking XRP to over 110 IBC-compatible chains. IBC stands for Inter-Blockchain Communication, a protocol that enables different blockchains to interact with one another. Coreum aimed to serve as a gateway for XRP holders to access various decentralized finance (DeFi) opportunities across this vast network.
#What Implications Does This Have for Cross-Chain Security?
The primary concern relating to this incident is the reliance on relayer-based verification rather than more secure on-chain cryptographic proofs. This design choice simplifies processes but compromises security. When a bridge depends on a set of relayers to verify occurrences on other chains, it places trust in their honesty and accuracy. If there is a flaw in the verification logic, as demonstrated in this case, the entire security model can fail.
Notably, no XRPL private keys were known to be compromised and the ledger itself remained intact. This is significant as it may mitigate the impact of the breach on the broader XRP ecosystem. The incident is classified as a failure of third-party infrastructure rather than a vulnerability within the protocol itself.