XRP Ledger patched decade-old bug that could create billions of dollars in XRP from nothing
Summary
A long-standing XRP Ledger flaw could have let attackers create and spend XRP without paying for it, bypassing the network’s fixed-supply protections. Researchers Cayden Liao and Veria AI disclosed the bug internally on Sept. 22, and RippleX reproduced it on a standalone server. The exploit used hundreds of accounts and a payment that triggered offers on the ledger’s built-in exchange, causing an arithmetic overflow: selling accounts received XRP while the buying account was charged almost nothing. RippleX found no evidence of exploitation on a public network. Developers patched the vulnerability in xrpld 3.4.1 on Sept. 25.
