Finst

XRP Ledger Fixes Bug That Could Create New XRP

RippleX patched an old flaw in the XRP Ledger that could, in theory, create extra XRP through the built-in DEX. There is no evidence of abuse on a public network.

XRP Ledger Fixes Bug That Could Create New XRP

Key Takeaways

  • RippleX patched an old flaw in the XRP Ledger that could, in theory, create new XRP without payment from the sender.
  • Researchers were able to reproduce the attack on a standalone server, but RippleX found no evidence of abuse on a public network.
  • The fix was released on September 25 in xrpld 3.4.1, while XRP is designed to have a fixed supply.

RippleX has patched an old flaw in the XRP Ledger that could, in theory, create new XRP without the sender paying for it. According to a security report, the bug could have undermined XRP's fixed supply, although RippleX says it found no evidence that the flaw was exploited on a public network.

Old Flaw in the Payment System

The vulnerability is said to date back to 2015 and was discovered by researcher Cayden Liao and Veria AI. They reported the issue internally on September 22. RippleX engineers were then able to reproduce the attack on a standalone server and confirmed that the newly created XRP could later be spent in a follow-up transaction.

The attack ran through the XRP Ledger's built-in exchange, where accounts can place offers to swap one token for another. In the scenario described by the researchers, an attacker would open hundreds of accounts, offer a small amount of one token for an extremely large amount of XRP in each one, and then make a single payment that hit all of those offers at once. Due to a calculation error, the system would miscount the XRP owed, fully paying the selling accounts while the buying account lost almost nothing.

Why This Matters for XRP

XRP was created all at once when the ledger launched in 2012. By design, no new XRP can be added. That is exactly why a bug that could still create extra XRP is especially sensitive for parties that rely on that fixed supply, such as institutional users and traders on crypto exchanges.

The XRP Ledger uses a low-latency consensus protocol that allows fast settlement without every participant needing to agree on every detail. That makes the network efficient, but it also shows how important correct checks in the software remain, especially for features like the DEX and the transaction processing around it.

Patch Without a Public Exploit

RippleX says it has found no signs that the bug was used on a public network. The researchers only needed a few hundred XRP for their method to open the accounts, most of which could later be recovered, plus transaction fees.

The fix was released on September 25 in xrpld 3.4.1, the ledger's server software, without an immediate explanation of exactly what was repaired. The incident fits into a series of long-hidden crypto vulnerabilities that have come to light over the past few months with help from AI, including flaws in wallet software and node software for Bitcoin.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.