The bug, believed to date to 2015, was found by researcher Cayden Liao and Veria AI and internally reported on Sept. 22. Engineers at RippleX, Ripple’s developer arm, reproduced the attack on a standalone server and confirmed the newly created XRP could be spent in a later transaction
RippleX said it found no evidence the flaw was exploited on any public network
All 100 billion XRP were created when the ledger launched in 2012, and its software is built so no more can ever be added. But the security vulnerability could have allowed an attacker to create XRP from nothing and sell it on exchanges, undercutting a supply cap that institutions using the network rely on
The attack worked through the ledger’s built-in exchange, where accounts post offers to swap one token for another
An attacker could have, theoretically, open hundreds of accounts, have each one offer a tiny amount of a token in exchange for an unusually large amount of XRP, then send a single payment that bought every offer at once
The total XRP owed would be too large for the software to count correctly, so the attacker’s selling accounts would be paid in full while the buying account was charged almost nothing — leaving the attacker with XRP that hadn’t existed before
The XRP Ledger runs a check after every transaction to make sure no new XRP has appeared, but that would have relied on the miscounted total and missed it. A separate limit on how much XRP a single account can receive wouldn’t have triggered either, because the attack spread the XRP across hundreds of accounts
The researchers’ method needed only a few hundred XRP to open those accounts, most of which could be recovered, plus transaction fees
Developers shipped the fix in xrpld 3.4.1, the ledger’s server software, on Sept. 25 without disclosing what it repaired
The incident joins a run of long-hidden crypto security flaws surfaced with AI help since July, including the Coldcard wallet bug behind the theft of at least 1,367 BTC and the vulnerabilities that forced Core Lightning to tell bitcoin node operators to disconnect
1One year after 10/10 flash crash, bitcoin and ether liquidity have rebuilt, but altcoins still face risks11 hours ago2Tokenized commodities look beyond gold as lending and oil open new markets11 hours ago3Bitcoin's $19 billion wake-up call: One-year after flash crash, has crypto learned anything?12 hours ago4Bitcoin's volatility has plunged, but extreme price swings are more frequent than in 201818 hours ago5Robinhood Chain slowdown spreads from fees to trading as transactions fall more than 40%19 hours ago6Visa survey says nearly half of APAC consumers open to using stablecoins by 203120 hours ago7U.S. CFTC moves to fold event contracts into swaps regulations as legal fight rages1 day ago8Robinhood Chain considers technology that gives paying traders priority1 day ago9New York AG secures up to $35 million and lifetime crypto ban from Celsius’ Alex Mashinsky1 day ago10Ledger investigates potential wallet tampering after reports of $86 million in crypto stolen1 day agoLatest Research Beyond the Risk-Free Rate: Diversified Real World Yield in Productive StablecoinsBeyond the Risk-Free Rate: Diversified Real World Yield in Productive StablecoinsDiversified RWA stablecoins sustain 5-7% yield from real credit as crypto funding compresses to ~4%. GENIUS pushes yield off-chain; TAM grows to $4B in 3 years
Diversified RWA stablecoins sustain 5-7% yield from real credit as crypto funding compresses to ~4%. GENIUS pushes yield off-chain; TAM grows to $4B in 3 years
Diversified RWA stablecoins sustain 5-7% yield from real credit as crypto funding compresses to ~4%. GENIUS pushes yield off-chain; TAM grows to $4B in 3 years