— A vulnerability dating back to 2015 could have enabled attackers to generate and spend newly created XRP, breaking the currency’s hard cap of 100 billion tokens.
— The flaw stemmed from a miscount in the ledger’s internal exchange, letting hundreds of accounts obtain large XRP sums while the purchaser paid virtually nothing.
— RippleX stated it saw no sign of the bug being abused on public networks and patched it in xrpld version 3.4.1 released on September 25.
A separate analysis of the XRP Ledger’s payment mechanism showed that an attacker could have minted substantial amounts of XRP without payment, violating the fixed‑supply rule, according to a security report issued Friday. The bug, traced to 2015, was uncovered by researcher Cayden Liao and Veria AI and reported internally on September 22.
RippleX engineers replicated the exploit on an isolated server and confirmed the fabricated XRP could later be spent. RippleX added that no public‑network abuse was detected.
When the ledger launched in 2012, all 100 billion XRP were created and the protocol forbids any further issuance. However, the discovered weakness could have let an attacker conjure XRP out of nothing and sell it on exchanges, eroding the supply limit that institutions depend on.
The exploit leveraged the ledger’s built‑in exchange, where users post offers to trade one token for another. In theory, an attacker could open hundreds of accounts, each offering a minuscule amount of a token in exchange for an unusually large XRP amount, then send a single payment that purchases every offer simultaneously.
Because the total XRP owed exceeded the software’s counting ability, the selling accounts would receive full payment while the buying account would be charged almost nothing, leaving the attacker with XRP that never existed before.
The ledger’s post‑transaction check for unexpected XRP would have relied on the erroneous total and thus missed the inflation. A per‑account receipt limit also would not have fired, since the attacker distributed the XRP across many accounts.
The researchers’ technique required only a few hundred XRP to fund the bogus accounts—most of which could be reclaimed—plus the usual transaction fees.
Developers deployed the fix in xrpld 3.4.1, the ledger’s server software, on September 25, without detailing the exact change.
This case adds to a series of long‑latent crypto security issues uncovered with AI assistance since July, such as the Coldcard wallet flaw that led to the theft of at least 1,367 BTC and the vulnerabilities that compelled Core Lightning to advise bitcoin node operators to disconnect.
Diversified RWA stablecoins sustain 5‑7% yield from real credit as crypto funding compresses to ~4%. GENIUS pushes yield off‑chain; TAM grows to $4B in 3 years.
Why this is significant:
Diversified RWA stablecoins sustain 5‑7% yield from real credit as crypto funding compresses to ~4%. GENIUS pushes yield off‑chain; TAM grows to $4B in 3 years.