1 min read
Add as a preferred source on Google

XRP Ledger Fixes Decade-Old Bug That Could Create XRP

The vulnerability in the payment engine was patched in xrpld 3.4.1 after researchers demonstrated unauthorized XRP creation in testing.

Mentioned assets
Open ledger book beside stacked metal tokens under inspection light / TokenPost.ai
Open ledger book beside stacked metal tokens under inspection light / TokenPost.ai

XRP Ledger fixed a roughly decade-old payment-engine vulnerability that could have allowed attackers to create spendable XRP without authorization, potentially exceeding the network’s total supply.

The flaw involved an unchecked 64-bit integer calculation when a payment consumed many offers from the on-chain order book. If the combined amount exceeded the maximum value, the calculation could wrap to a much smaller number while sellers still received the full amounts. The difference could become newly created XRP.

An attacker could have prepared hundreds of accounts with offers for very large amounts of XRP and then used another account to consume them in one payment. The vulnerability may have existed since 2015, when the current payment engine was developed.

The fix shipped with xrpld 3.4.1 on Sept. 25. It was applied without the network’s usual amendment vote, which normally requires more than 80% support from trusted validators for two consecutive weeks. The emergency approach was intended to prevent the vulnerability from remaining exposed during a public voting period.

No evidence indicates the flaw was exploited on a public network. The same release also addressed a separate issue in the batch-transaction feature, which was not active on the main network and did not affect user funds.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…