XRP Ledger Fixes Critical 11-Year-Old Bug That Could "Mint" XRP via Crafted Payments

AI Market Summary
XRPL patched a critical payment-path calculation flaw that could have enabled attackers to effectively mint and spend large amounts of XRP via crafted offers and a single payment transaction, threatening ledger integrity and supply constraints. RippleX says there is no evidence of exploitation on public networks, which limits immediate panic, but the disclosure elevates near-term operational and reputational risk for the XRP ecosystem and related liquidity venues until upgrade adoption is widespread.
Impact level
● High
Affected assets
XRP/USDT+0.42%
AI Insight · XRP/USDTAI Insight
● Neutral
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Huoxing Finance reported that the XRP Ledger has patched a payment-related vulnerability that may date back to 2015. The flaw could let an attacker evade exchange-calculation limits by submitting a specially crafted payment, effectively creating and spending large amounts of XRP and weakening the safeguard intended to cap total XRP supply at 10 billion. According to the disclosure, an attacker could create hundreds of accounts, post offers swapping tiny amounts of tokens for huge quantities of XRP, then use a single payment to fill all offers at once. Because of an error in the software's aggregation of transaction totals, seller accounts could receive the full XRP proceeds while buyer accounts would pay almost nothing. Researchers Cayden Liao and Veria AI reported the issue on September 22. RippleX later reproduced the attack and confirmed that the generated XRP could be used in subsequent transactions. RippleX said it has found no evidence the vulnerability was exploited on any public network. A fix was released in xrpld version 3.4.1 on September 25.