Home/News/XRP Ledger patched decade-old bug that could create billions of dollars in XRP from nothing
XRPUSD

XRP Ledger patched decade-old bug that could create billions of dollars in XRP from nothing

CoinDeskPublished on 3 hours ago

Researchers demonstrated how a payment could create spendable XRP without the sender funding it, prompting an emergency software release.

XRP Ledger patched decade-old bug that could create billions of dollars in XRP from nothing

Researchers demonstrated how a payment could create spendable XRP without the sender funding it, prompting an emergency software release.

A flaw dating to 2015 could have allowed attackers to create and spend new XRP, violating the cryptocurrency’s fixed supply of 100 billion tokens. The vulnerability exploited a counting error in the XRP Ledger’s built-in exchange, allowing hundreds of accounts to receive large amounts of XRP while the buyer paid almost nothing. RippleX said it found no evidence of exploitation on public networks and fixed the flaw in the xrpld 3.4.1 software release on Sept. 25.

A flaw in the XRP Ledger’s payment system could have let an attacker create large amounts of new XRP without paying for it, breaking the token’s fixed-supply rule, according to a security report published Friday.

The bug, believed to date to 2015, was found by researcher Cayden Liao and Veria AI and internally reported on Sept. 22. Engineers at RippleX, Ripple’s developer arm, reproduced the attack on a standalone server and confirmed the newly created XRP could be spent in a later transaction.

RippleX said it found no evidence the flaw was exploited on any public network.

All 100 billion XRP were created when the ledger launched in 2012, and its software is built so no more can ever be added. But the security vulnerability could have allowed an attacker to create XRP from nothing and sell it on exchanges, undercutting a supply cap that institutions using the network rely on.

The attack worked through the ledger’s built-in exchange, where accounts post offers to swap one token for another.

An attacker could have, theoretically, open hundreds of accounts, have each one offer a tiny amount of a token in exchange for an unusually large amount of XRP, then send a single payment that bought every offer at once.

The total XRP owed would be too large for the software to count correctly, so the attacker’s selling accounts would be paid in full while the buying account was charged almost nothing — leaving the attacker with XRP that hadn’t existed before.

The XRP Ledger runs a check after every transaction to make sure no new XRP has appeared, but that would have relied on the miscounted total and missed it. A separate limit on how much XRP a single account can receive wouldn’t have triggered either, because the attack spread the XRP across hundreds of accounts.

The researchers’ method needed only a few hundred XRP to open those accounts, most of which could be recovered, plus transaction fees.

Developers shipped the fix in xrpld 3.4.1, the ledger’s server software, on Sept. 25 without disclosing what it repaired.

The incident joins a run of long-hidden crypto security flaws surfaced with AI help since July, including the Coldcard wallet bug behind the theft of at least 1,367 BTC and the vulnerabilities that forced Core Lightning to tell bitcoin node operators to disconnect.

Read More: XRP Ledger adds new controls for banks, stablecoins and tokenized funds

1Robinhood Chain slowdown spreads from fees to trading as transactions fall more than 40%25 minutes ago 2Visa survey says nearly half of APAC consumers open to using stablecoins by 20312 hours ago 3U.S. CFTC moves to fold event contracts into swaps regulations as legal fight rages7 hours ago 4Robinhood Chain considers technology that gives paying traders priority10 hours ago 5New York AG secures up to $35 million and lifetime crypto ban from Celsius’ Alex Mashinsky14 hours ago 6Ledger investigates potential wallet tampering after reports of $86 million in crypto stolen14 hours ago 7DWF Labs subsidiaries sue BitGo for $141 million over alleged token lock-up breach16 hours ago 8Zcash developers set January target for quantum-resistant payments after ‘bunker mode’ scare17 hours ago 9Trump's Iran pledge underpins crypto gains as bitcoin bears face liquidation pressure18 hours ago 10Bitcoin steadies near $82,500 after Trump rules out Iran strike before midterms18 hours ago

Beyond the Risk-Free Rate: Diversified Real World Yield in Productive Stablecoins

Beyond the Risk-Free Rate: Diversified Real World Yield in Productive Stablecoins

Diversified RWA stablecoins sustain 5-7% yield from real credit as crypto funding compresses to ~4%. GENIUS pushes yield off-chain; TAM grows to $4B in 3 years.

Diversified RWA stablecoins sustain 5-7% yield from real credit as crypto funding compresses to ~4%. GENIUS pushes yield off-chain; TAM grows to $4B in 3 years.

Why it matters:

Diversified RWA stablecoins sustain 5-7% yield from real credit as crypto funding compresses to ~4%. GENIUS pushes yield off-chain; TAM grows to $4B in 3 years.

Zcash developers set January target for quantum-resistant payments after ‘bunker mode’ scare

Solana is about to halve its block times as final 200-millisecond upgrade nears

XRP Ledger adds new controls for banks, stablecoins and tokenized funds