XRP Ledger Patches Decade-Old Security Flaw That Could Have Printed Billions in XRP
A hidden flaw could have broken XRP's fixed supply
A security flaw in the XRP Ledger could have let an attacker create large amounts of new XRP without paying for it. The bug dates back to 2015 and was discovered by researcher Cayden Liao and Veria AI.
RippleX, the developer arm of Ripple, said it found no evidence the flaw was ever used on any public network. Engineers reproduced the attack on a standalone server and confirmed the newly created XRP could have been spent in a later transaction.
The fix shipped in the xrpld 3.4.1 software release on Sept. 25. Developers did not disclose the exact details of what was repaired.
How the vulnerability worked
- The bug lived in the XRP Ledger's built-in exchange, where accounts post offers to swap one token for another
- An attacker could open hundreds of accounts and have each offer a tiny amount of one token for a huge amount of XRP
- A single payment could then buy every offer at once
- A counting error meant the attacker paid almost nothing while receiving far more XRP than intended
The attacker needed only a few hundred XRP to open those accounts, most of which could be recovered, plus standard transaction fees.
Why this matters for the network
All 100 billion XRP were created when the ledger launched in 2012. The software is designed so no more can ever be added. The security vulnerability could have allowed someone to create XRP from nothing and sell it on exchanges.
The ledger runs a check after every transaction to make sure no new XRP has appeared. But that check relied on the same miscounted total and would have missed it. A separate limit on how much XRP a single account can receive would not have triggered either, because the attack spread the XRP across hundreds of accounts.
Institutions using the network rely on the supply cap. Breaking it would have undermined trust in that fixed limit.
The fix and broader context
The incident joins a run of long-hidden crypto security flaws surfaced with AI help since July. This includes the Coldcard wallet bug behind the theft of at least 1,367 BTC and vulnerabilities that forced Core Lightning to tell bitcoin node operators to disconnect.
RippleX said its investigation found no signs that anyone exploited the XRP Ledger flaw. The network's fixed-supply rule remains intact.