XRP Ledger Fixes Long-Running Bug That Could Have Minted Billions of XRP

AI مارکیٹ کا خلاصہ
A security report disclosed a long-standing XRP Ledger flaw that could have enabled "XRP-from-nothing" creation via miscounting in the built-in exchange, potentially undermining the fixed-supply assumption. RippleX states there is no evidence of exploitation on public networks, and the issue was patched in xrpld 3.4.1. Near-term impact centers on XRPL infrastructure trust, institutional risk controls, and exchange due-diligence around protocol integrity.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
XRP/USDT+0.41%
AI تجزیاتی سمجھ · XRP/USDTAI تجزیاتی سمجھ
● Neutral
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
A vulnerability in the XRP Ledger's payment logic could have allowed an attacker to generate vast amounts of XRP at no cost, violating the network's fixed-supply design, according to a security report released Friday. The issue, believed to date back to 2015, was discovered by researcher Cayden Liao and Veria AI and privately disclosed on Sept. 22. RippleX, Ripple's developer arm, said its engineers reproduced the exploit on an isolated server and confirmed that the newly created XRP could be spent in subsequent transactions. RippleX added it has found no indication the flaw was used on any public network. XRP Ledger launched in 2012 with the full 100 billion XRP created at genesis, and the protocol is designed to prevent any additional issuance. The reported bug could have undermined that supply cap by enabling an attacker to create XRP 'from nothing' and potentially sell it on exchanges, a risk for institutions that rely on the fixed-supply premise. The exploit route ran through the ledger's built-in exchange, where users post offers to swap assets. An attacker would create hundreds of accounts and have each place an offer exchanging a tiny amount of a token for an unusually large amount of XRP. The attacker would then submit a single payment that simultaneously consumed all offers. Because the total XRP owed would overflow or be miscounted, the accounts selling XRP would be paid in full while the buying account would be debited almost nothing, effectively producing XRP that did not previously exist. A post-transaction invariant check intended to ensure no new XRP appeared would also fail to catch the minting because it depended on the same miscalculated total. An additional cap on how much XRP a single account can receive would not have been triggered either, since the attacker would distribute the proceeds across hundreds of accounts. Researchers said the setup required only a few hundred XRP to fund account creation, most of which could be recovered, plus transaction fees. Developers shipped a patch in xrpld 3.4.1 on Sept. 25, without publicly specifying what the update fixed. The disclosure adds to a recent series of long-dormant crypto security issues surfaced with AI assistance since July, including a Coldcard wallet bug tied to the theft of at least 1,367 BTC and vulnerabilities that prompted Core Lightning to advise bitcoin node operators to disconnect. Read more: XRP Ledger adds new controls for banks, stablecoins and tokenized funds