XRP Ledger Patches Decade-Old Security Flaw That Could Have Printed Billions in XRP

Oct 10, 2026 16:07 Written by Newisty Editorial Team xrp security bug blockchain ripple
XRP Ledger Patches Decade-Old Security Flaw That Could Have Printed Billions in XRP

A hidden flaw could have broken XRP's fixed supply

A security flaw in the XRP Ledger could have let an attacker create large amounts of new XRP without paying for it. The bug dates back to 2015 and was discovered by researcher Cayden Liao and Veria AI.

RippleX, the developer arm of Ripple, said it found no evidence the flaw was ever used on any public network. Engineers reproduced the attack on a standalone server and confirmed the newly created XRP could have been spent in a later transaction.

The fix shipped in the xrpld 3.4.1 software release on Sept. 25. Developers did not disclose the exact details of what was repaired.

How the vulnerability worked

  • The bug lived in the XRP Ledger's built-in exchange, where accounts post offers to swap one token for another
  • An attacker could open hundreds of accounts and have each offer a tiny amount of one token for a huge amount of XRP
  • A single payment could then buy every offer at once
  • A counting error meant the attacker paid almost nothing while receiving far more XRP than intended

The attacker needed only a few hundred XRP to open those accounts, most of which could be recovered, plus standard transaction fees.

Why this matters for the network

All 100 billion XRP were created when the ledger launched in 2012. The software is designed so no more can ever be added. The security vulnerability could have allowed someone to create XRP from nothing and sell it on exchanges.

The ledger runs a check after every transaction to make sure no new XRP has appeared. But that check relied on the same miscounted total and would have missed it. A separate limit on how much XRP a single account can receive would not have triggered either, because the attack spread the XRP across hundreds of accounts.

Institutions using the network rely on the supply cap. Breaking it would have undermined trust in that fixed limit.

The fix and broader context

The incident joins a run of long-hidden crypto security flaws surfaced with AI help since July. This includes the Coldcard wallet bug behind the theft of at least 1,367 BTC and vulnerabilities that forced Core Lightning to tell bitcoin node operators to disconnect.

RippleX said its investigation found no signs that anyone exploited the XRP Ledger flaw. The network's fixed-supply rule remains intact.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!