The tx team made the following statement regarding the incident:
“The bridge software incorrectly recorded transactions as investments that didn’t actually deliver any $XRP to the bridge, and minted bridged $XRP on the tx chain in return. The attacker then used these unbacked balances to withdraw real $XRP from the reserve.”
The company also stated that the bridge in question underwent multiple internal and third-party security audits before being made available, but the attacker exploited a previously undetected vulnerability.
The amount stolen is estimated to be 200,000 $XRP (approximately $200,000).
According to information shared by tx, the impact of the attack was limited to bridged $XRP on the tx chain. Following the attack, it was stated that all bridged $XRP in circulation is no longer backed one-to-one with actual $XRP reserves.
Other bridged assets were reportedly fully secured.
The team also emphasized that tokens and user funds held on centralized exchanges, decentralized exchanges, or directly on the blockchain were not affected by the incident.
Following the detection of the incident, the bridge between XRPL and tx was shut down. It was reported that the security vulnerability was identified and the necessary corrections were made to the code that caused the vulnerability.
Other steps taken by the tx team following the attack include tracking the movement of stolen funds across different blockchain networks and working with blockchain forensics companies.
The company also announced that it has filed a formal complaint with the FBI Internet Crime Complaint Center (IC3), including all transaction records related to the attack and additional information that could help identify the attacker.
tx management stated that different options are being evaluated regarding how to compensate users affected by the incident.
The company stated that details regarding the compensation mechanism to be implemented and the timeline of the process will be shared in a new announcement to be made later.
However, tx announced that all available legal avenues will be pursued to identify and prosecute the attacker.
The XRPL-tx bridge will remain closed until security reviews and system upgrades are complete.
*This is not investment advice.