Loading prices…
🩸BEARISH

XRP Ledger flaw could mint 18T XRP, forcing emergency fix

No XRP was created or lost, but the incident exposed a decade-old weakness in XRPL's supply controls and forced developers to bypass normal validator approval.

An AI security system uncovered an XRP Ledger vulnerability that could have let an attacker create roughly 18 trillion XRP through a single payment transaction, about 180 times the network's original 100 billion supply. The flaw threatened the integrity of XRP's fixed-supply model and its reported $94 billion market capitalization, but RippleX found no evidence of exploitation and confirmed that no unauthorized XRP was created.

Why it matters

The weakness combined two flaws in XRPL's payment and supply-protection code. A deliberately constructed set of trading offers could trigger an integer overflow, allowing a seller to receive the full XRP payment while the buyer was charged only a fraction. The same faulty arithmetic could prevent the supply safeguard from detecting the newly created XRP.

The payment-engine code dated to 2015, while the affected safeguard was introduced in 2017. The issue survived more than a dozen audits and security contests, including one with a $550,000 prize pool, before Veria Labs' AI system identified and reproduced it on a local network. Veria received a $250,000 bounty.

Market impact

Developers patched the vulnerability three days after it was reported on Sept. 22 and publicly disclosed it on Oct. 9. RippleX, the XRP Ledger Foundation and validators deployed version 3.4.1 outside XRPL's normal amendment process, which requires more than 80% validator support for two consecutive weeks.

The emergency approach reduced the risk of counterfeit XRP entering circulation but introduced a temporary consensus risk between upgraded and outdated servers. More than 80% of trusted validators had upgraded by Sept. 25. RippleX now plans broader AI-assisted testing, stronger adversarial reviews and more formal verification of legacy XRPL components.

Related tokens
$XRP

Frequently asked questions

  1. How much XRP could the vulnerability have created?

    The flaw could have allowed roughly 18 trillion XRP to be created through a single payment transaction, about 180 times the original 100 billion supply.

  2. Was any unauthorized XRP created or lost?

    No. RippleX confirmed that no unauthorized XRP was created, no funds were lost and investigators found no evidence of exploitation on public networks.

  3. How did the XRPL vulnerability work?

    An integer overflow could miscalculate the buyer's payment, while a second flaw could prevent the supply safeguard from detecting the newly created XRP.

  4. Why did XRPL bypass its normal amendment process?

    Developers concluded that waiting for the usual validator approval process would leave the vulnerability exposed and could allow attackers to exploit it before the fix activated.

  5. What changes is RippleX making after the security incident?

    RippleX plans to expand AI-assisted vulnerability discovery, increase adversarial testing, strengthen formal verification and retest resolved findings against release candidates.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →