XRP Ledger Patches Critical Flaw That Risked Creating Billions of Tokens

A newly disclosed security flaw in the XRP Ledger could have allowed attackers to create large amounts of spendable XRP without paying for the tokens, potentially violating the network’s fixed-supply limit. The discovery led developers to release a software update to eliminate the vulnerability.

According to a security report published Friday, the bug may have existed since 2015. Researcher Cayden Liao and Veria AI identified the issue and reported it privately on Sept. 22.

RippleX, Ripple’s development division, reproduced the attack on an isolated server and confirmed that the artificially generated XRP could be used in subsequent transactions. The company said it had found no evidence that the vulnerability had been exploited on any public network.

The XRP Ledger began operating in 2012 with a total supply of 100 billion XRP, and its protocol is designed to prevent additional tokens from entering circulation. However, the vulnerability could have allowed an attacker to bypass that restriction, create new XRP and potentially sell the tokens on cryptocurrency exchanges.

The exploit relied on a weakness in the ledger’s built-in decentralized exchange, where users submit offers to trade one token for another. An attacker could theoretically establish hundreds of accounts, each offering a small quantity of another token in exchange for an unusually large amount of XRP.

By submitting a single payment that executed all the offers simultaneously, the attacker could exploit an error in the software’s calculation of the total XRP required. The selling accounts could receive the promised XRP while the purchasing account was charged almost nothing, effectively generating tokens without the necessary payment.

The XRP Ledger normally verifies transactions to ensure that its total supply does not increase unexpectedly. However, the vulnerability could have caused this check to rely on an incorrectly calculated figure, allowing the newly created tokens to go undetected.

Another safeguard designed to limit the amount of XRP received by an individual account would not necessarily have stopped the attack. Distributing the tokens across hundreds of accounts could have kept each account below the applicable threshold.

Researchers estimated that the method required only a few hundred XRP to establish the accounts, along with transaction fees. Most of the initial funds could have been recovered afterward.

Developers fixed the issue in version 3.4.1 of xrpld, the XRP Ledger’s server software, released on Sept. 25. The update was issued before the specific vulnerability was publicly disclosed.

The discovery adds to a growing list of longstanding cryptocurrency security weaknesses identified with help from artificial intelligence since July. Other incidents include a Coldcard wallet vulnerability associated with the theft of at least 1,367 BTC and flaws that prompted Core Lightning to advise Bitcoin node operators to disconnect their systems.