Crypto & Markets

XRP Ledger Patches Decade-Old Bug That Could Create XRP from Nothing

A decade-old security flaw in the XRP Ledger could have enabled attackers to create and spend new XRP tokens without paying for them.

What Happened

Researchers demonstrated how a payment could create spendable XRP without the sender funding it, prompting an emergency software release.

The flaw was demonstrated by Cayden Liao and Veria AI. It was internally reported.

Engineers at RippleX, Ripple’s developer arm, reproduced the attack on a standalone server and confirmed the newly created XRP could be spent in a later transaction.

Key Facts

  • It exploited a counting error in the XRP Ledger’s built-in exchange.
  • Attackers could have opened hundreds of accounts, each offering a tiny amount of a token in exchange for an unusually large amount of XRP.
  • A single payment would have bought every offer at once, resulting in a miscounted total.
  • The buying account would be charged almost nothing, while the selling accounts received full payment.
  • The total XRP created would not exist in the ledger’s original supply of 100 billion tokens.
  • The fix was released in version xrpld 3.4.1.
  • RippleX found no evidence of exploitation on public networks.

How It Worked

The XRP Ledger originally launched in 2012 with a fixed supply of 100 billion tokens. No new XRP should ever be created.

The vulnerability occurred in the ledger’s built-in exchange. When accounts posted offers to swap one token for another, the system calculated the total XRP owed.

Due to a counting error, the system would misrepresent the total amount of XRP involved. The attacker’s offers were processed as if they were valid, but the total was too large to be accurate.

After the transaction, the ledger failed to detect the miscount. The new XRP was not flagged as invalid. It could be spent in subsequent transactions.

Why It Matters

The fixed supply of XRP is a foundational principle for many institutions using the network.

If an attacker could generate new XRP without funding it, they could sell it on exchanges. This would undercut the supply cap and potentially destabilize price expectations.

AI-generated conceptual illustration: XRP Ledger Patches Decade-Old Bug That Could Create XRP from Nothing
AI-generated conceptual illustration; not a photograph or a factual data chart.

For financial institutions relying on XRP for settlement, this flaw posed a risk to the integrity of the system.

Limitations and Open Questions

The vulnerability did not allow the creation of massive amounts of XRP. It required only a few hundred XRP to open those accounts.

Most of these accounts could be recovered, reducing the practical impact.

There is no evidence the flaw was exploited on public networks. RippleX confirmed this.

It remains unclear whether similar vulnerabilities exist in other blockchain systems.

What to Watch Next

Security researchers are continuing to analyze the XRP Ledger’s architecture.

Future updates may include additional safeguards for payment systems.

Users are advised to stay updated on official releases from RippleX.

Source: Coindesk

Sources & further reading

AI-generated illustration.

Show More

Related Articles

Back to top button