1 min read
Add as a preferred source on Google

RippleX Finds No Evidence of Exploitation After XRPL Patch

The emergency xrpld 3.4.1 release fixed an integer-overflow bug that could have created spendable XRP beyond the ledger’s supply rules.

Mentioned assets
Closed metal ledger beside a repaired exchange mechanism / TokenPost.ai
Closed metal ledger beside a repaired exchange mechanism / TokenPost.ai

RippleX disclosed that no evidence of exploitation has been found after developers fixed an XRP Ledger flaw that could have created spendable XRP outside the network’s intended supply rules.

The integer-overflow vulnerability affected xrpld 3.4.0 and earlier and was reported through the XRPL Bug Bounty program on Sept. 22. RippleX reproduced the issue on a standalone server and confirmed that newly created XRP could be spent in a later payment.

Processing numerous order-book offers could cause the arithmetic to overflow, miscalculating the buyer’s payment while crediting sellers with the full amounts.

Developers released xrpld 3.4.1 on Sept. 25 with overflow checks and a wider safety counter designed to prevent XRP creation. More than 80% of default Unique Node List validators were running the patched version or a later release that day.

An exploit would have involved arranging hundreds of offers at specific prices before submitting a single payment. The setup would have tied up several hundred XRP in account and offer reserves, along with fees, most of which could later be reclaimed.

“We have found no evidence that this issue was exploited on any public network,” RippleX said. The vulnerability appears to have existed since the payment engine was written in 2015.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…