XRP Ledger Patches Decade-Old Bug That Could Have Created Billions in XRP
According to a security report published on Friday, a decade-old flaw in the XRP Ledger payment system could have allowed an attacker to create large amounts of new XRP without paying for it, undermining the token's fixed-supply rule. The vulnerability, believed to date back to 2015, was discovered by researcher Cayden Liao and Veria AI, and was reported internally on September 22. RippleX developers reproduced the attack and shipped a fix in the xrpld 3.4.1 server software on September 25. RippleX reported finding no evidence that the vulnerability was exploited on any public network.
Key points
- A flaw dating back to 2015 in the XRP Ledger could have allowed unbacked XRP creation, violating its fixed-supply rule.
- The vulnerability was discovered by researcher Cayden Liao and Veria AI, then reported internally on Sept. 22.
- RippleX developers reproduced the attack on a standalone server and shipped a fix in xrpld 3.4.1 on Sept. 25.
- RippleX stated there is no evidence the flaw was ever exploited on any public network.
What Happened
A security report published on Friday revealed that a flaw in the XRP Ledger payment system could have allowed an attacker to generate large amounts of new XRP without payment, effectively breaking the token's fixed-supply rule. The vulnerability is believed to date back to 2015.
The issue was discovered by researcher Cayden Liao and Veria AI and was internally reported on September 22. RippleX, the developer arm of Ripple, reproduced the attack on a standalone server and confirmed that newly created XRP could be spent in a later transaction.
What Changed
To address the vulnerability, developers shipped a fix in xrpld 3.4.1, the ledger's server software, on September 25 without initially disclosing what the update repaired. RippleX stated it found no evidence that the flaw was ever exploited on any public network.
Availability
The security patch is included in xrpld server software version 3.4.1, which was released to network operators on September 25.
Why it matters
The vulnerability threatened the fixed-supply guarantee that institutions and users rely on when utilizing the XRP Ledger, highlighting ongoing security audits involving complex ledger and built-in exchange mechanisms.
What we know
- A flaw in the XRP Ledger payment system dating to 2015 could have allowed an attacker to create large amounts of new XRP.
- The bug was found by researcher Cayden Liao and Veria AI and internally reported on Sept. 22.
- RippleX found no evidence the flaw was exploited on any public network.
- Developers shipped a fix in xrpld 3.4.1 server software on Sept. 25.
What remains unclear
- Whether any other hidden exploits exist within the ledger's built-in exchange mechanism remains unknown.