Skip to content

XRP Ledger Fixes Major Vulnerability That Went Unnoticed for Nearly 11 Years, Attackers Could Have Exploited It to Generate XRP Out of Thin Air

Oct 10, 12:23

October 10 - The XRP Ledger recently fixed a payment system vulnerability that may date back to 2015. The vulnerability could have allowed attackers to bypass the system's calculation limits on token exchange amounts through a specially crafted payment transaction, generating and spending large amounts of XRP out of thin air, undermining the mechanism that caps the total XRP supply at 100 billion.

According to disclosures, attackers could create hundreds of accounts, have these accounts place offers to exchange small amounts of tokens for massive amounts of XRP, and then settle them all at once through a single payment. Due to a flaw in the software's calculation of the total transaction amount, the seller accounts could receive the full XRP while the buyer accounts would barely need to pay the corresponding amount.

Researchers Cayden Liao and Veria AI reported the vulnerability on September 22, and RippleX subsequently reproduced the attack and confirmed that the generated XRP could be used in subsequent transactions. RippleX stated that there is currently no evidence that the vulnerability was ever exploited on any public network. The development team released xrpld version 3.4.1 on September 25 to fix the vulnerability.

Source