Researchers found that an XRP Ledger flaw dating to 2015 could have let attackers create and spend new XRP without properly funding the transaction. The bug was disclosed internally on Sept. 22, reproduced by RippleX engineers, and fixed in the xrpld 3.4.1 release on Sept. 25. RippleX said it found no evidence of exploitation on public networks.
The vulnerability challenged a core assumption behind XRP: all 100 billion tokens were created when the ledger launched in 2012, and the software is designed to prevent additional issuance. An attacker could have opened hundreds of accounts, posted offers to exchange small amounts of another token for unusually large amounts of XRP, and triggered them with a single payment.
Why it matters
The ledger’s built-in exchange miscounted the total XRP owed across those offers. Selling accounts could then receive the full amount while the buying account paid almost nothing, creating spendable XRP that had not existed before. The ledger’s post-transaction supply check relied on the same incorrect total, while the account-level receiving limit could be bypassed by distributing the funds across hundreds of accounts.
The method required only a few hundred XRP to open the accounts, most of which could be recovered, plus transaction fees. That low setup cost made the flaw more serious than a theoretical accounting error, even though no public-network exploitation has been identified.
Market impact
The patch removes the disclosed vulnerability, but the episode puts attention on the controls supporting XRP’s fixed-supply model and on how quickly operators adopt xrpld 3.4.1. A successful exploit could have allowed attackers to sell newly created XRP on exchanges and undermine confidence in the supply cap.
The incident also adds to a recent series of long-hidden crypto security flaws, including bugs affecting Coldcard wallets and Bitcoin’s Core Lightning software. For XRP Ledger users, the immediate issue is software updates and continued monitoring of public networks for evidence of abuse.
Frequently asked questions
-
How could the XRP Ledger flaw create new XRP?
A counting error in the built-in exchange could let selling accounts receive large XRP amounts while the buying account paid almost nothing. The resulting XRP could then be spent in later transactions.
-
What was the role of the attacker’s multiple accounts?
The attacker could spread the newly created XRP across hundreds of accounts. That avoided a separate limit on how much XRP a single account could receive.
-
Did the flaw violate XRP’s fixed-supply design?
The vulnerability could have allowed new spendable XRP to appear despite the ledger’s 100 billion token cap. All 100 billion XRP were created when the ledger launched in 2012.
-
Was the vulnerability exploited on a public XRP Ledger network?
RippleX said it found no evidence that the flaw was exploited on public networks. Its engineers reproduced the attack on a standalone server.
-
How was the XRP Ledger vulnerability fixed?
Developers fixed the flaw in xrpld 3.4.1, the ledger’s server software, released on Sept. 25. The issue had been internally reported three days earlier.
CoinDesk