×

XRPL Addresses 10-Year-Old Exploit That Could Have Generated Billions in Fake XRP

XRPL Addresses 10-Year-Old Exploit That Could Have Generated Billions in Fake XRP

A decade-old vulnerability in the XRP Ledger could have enabled attackers to generate new XRP without paying for it, potentially bypassing the network’s fixed-supply limit. The security issue was discovered by researchers and led to a software update designed to prevent the exploit.

According to a report released Friday, the flaw may have existed since 2015. Researcher Cayden Liao and Veria AI identified the vulnerability and privately reported it on Sept. 22.

RippleX, Ripple’s developer division, recreated the attack on an isolated server and confirmed that the unauthorized XRP could be spent in later transactions. The team said it had found no evidence that the flaw had been exploited on any public network.

The XRP Ledger launched in 2012 with a total supply of 100 billion XRP. Its underlying software is designed to ensure that no additional tokens can be created. However, the vulnerability could have allowed an attacker to circumvent this protection, generate new XRP and potentially sell it through cryptocurrency exchanges.

The exploit targeted the XRP Ledger’s built-in decentralized exchange, which allows users to create offers to swap one token for another.

Researchers demonstrated that an attacker could theoretically open hundreds of accounts, each offering a small amount of another token in exchange for an unusually large quantity of XRP. A single payment could then execute all those offers simultaneously.

The software could miscalculate the combined amount of XRP needed to complete the transactions. This would allow the selling accounts to receive their requested XRP while the purchasing account paid almost nothing, effectively creating tokens without the necessary funds.

Although the ledger checks transactions to ensure that its total XRP supply does not increase unexpectedly, the flawed calculation could have caused the verification mechanism to miss the newly created tokens.

An additional safeguard restricting how much XRP an individual account can receive would not necessarily have prevented the attack. By distributing the tokens across hundreds of accounts, an attacker could have avoided triggering the individual account limits.

The researchers said the exploit required only a few hundred XRP to establish the necessary accounts, along with transaction fees. Most of the initial funds could subsequently have been recovered.

Developers patched the vulnerability in version 3.4.1 of xrpld, the XRP Ledger’s server software, released on Sept. 25. The update was issued without initially disclosing the specific flaw it addressed.

The incident adds to a growing number of previously hidden cryptocurrency security weaknesses uncovered with the assistance of artificial intelligence since July. Other cases include a Coldcard wallet vulnerability linked to the theft of at least 1,367 BTC and flaws that led Core Lightning to advise Bitcoin node operators to disconnect their systems.

Share this content:

Copyright © 2025 CoinsNewz