Long-Standing XRP Ledger Bug Fixed After Revealing Risk of Unlimited XRP Creation

Security researchers have uncovered a vulnerability in the XRP Ledger that could have allowed attackers to create billions of dollars’ worth of XRP without providing the required funds. The flaw threatened the network’s fixed-supply mechanism and prompted developers to issue a software patch.

A report published Friday revealed that the vulnerability may have remained undetected since 2015. Researcher Cayden Liao and Veria AI identified the bug and privately notified the relevant team on Sept. 22.

RippleX, Ripple’s development arm, successfully reproduced the attack on an isolated server and verified that the newly generated XRP could be spent in later transactions. However, the team reported no evidence that the exploit had been used against any public network.

The XRP Ledger launched in 2012 with a fixed supply of 100 billion XRP, and its protocol is designed to prevent the creation of additional tokens. The security flaw could have undermined that restriction, potentially allowing attackers to generate unauthorized XRP and sell it on cryptocurrency exchanges.

The attack exploited a weakness in the XRP Ledger’s built-in decentralized exchange, which enables users to place offers to swap different tokens.

In a theoretical attack, a malicious actor could establish hundreds of accounts, each offering a small amount of another token in exchange for a disproportionately large quantity of XRP. A single payment could then execute all the offers at once.

The vulnerability caused the software to miscalculate the total XRP required to settle the transactions. Consequently, the selling accounts could receive the full amount of XRP they requested, while the purchasing account would be charged almost nothing. This discrepancy could effectively create new tokens without the corresponding payment.

Although the XRP Ledger performs checks after transactions to ensure that its total supply has not increased, the flawed calculation could have caused the verification process to overlook the unauthorized XRP.

A separate safeguard that restricts how much XRP an individual account can receive would also have been insufficient. By spreading the newly generated tokens across hundreds of accounts, an attacker could have avoided triggering the account-level limit.

According to the researchers, the attack required only a few hundred XRP to create the necessary accounts, plus transaction fees. Most of the initial XRP used could have been recovered.

Developers resolved the vulnerability in version 3.4.1 of xrpld, the XRP Ledger’s server software, released on Sept. 25. The patch was distributed without initially revealing the specific security issue it addressed.

The discovery comes amid a series of long-standing cryptocurrency vulnerabilities identified with assistance from artificial intelligence since July. Other cases include a Coldcard wallet flaw linked to the theft of at least 1,367 BTC and vulnerabilities that prompted Core Lightning to advise Bitcoin node operators to disconnect their systems.

  • Related Posts

    Robinhood Chain Momentum Weakens as Transaction Counts Fall Over 40%

    Robinhood Chain has recorded a steep decline in network usage, with average daily transactions dropping from 10.8 million in mid-September to 6.2 million in early October. The slowdown comes as…

    Continue reading
    U.S. Regulator Targets Event Contract Rules as Legal Challenges Intensify

    The U.S. Commodity Futures Trading Commission (CFTC) is moving to strengthen its authority over prediction markets through new regulatory measures designed to classify certain event contracts as swaps. The initiative…

    Continue reading