A critical flaw in the XRP Ledger dating back to 2015 could have allowed attackers to create and spend new XRP tokens, violating the cryptocurrency’s fixed supply cap of 100 billion tokens. The vulnerability stemmed from a counting error in the ledger’s built-in exchange, enabling attackers to receive large amounts of XRP while paying nearly nothing.
The bug was discovered by researcher Cayden Liao and Veria AI and reported to RippleX, Ripple’s developer arm, on September 22. Engineers at RippleX confirmed the flaw by reproducing the attack on a standalone server, demonstrating that newly created XRP could be spent in subsequent transactions.
RippleX stated that there was no evidence of the flaw being exploited on any public network. The issue was patched in the xrpld 3.4.1 software release on September 25. The attack exploited the ledger’s exchange by allowing hundreds of accounts to post offers swapping small amounts of tokens for large amounts of XRP, resulting in a miscounted total that left attackers with free XRP.
The XRP Ledger’s transaction checks and account limits would not have prevented the attack, as the fraudulent XRP was spread across multiple accounts. The researchers noted that the method required only a few hundred XRP to open accounts, plus transaction fees, to execute the exploit.