October 10, 2026

Real-Time Crypto Insights, News And Articles

XRP Ledger Fixes 10-Year-Old Bug That Could Have Created Billions of XRP

Security researchers uncovered a vulnerability in the XRP Ledger’s payment system that could have allowed attackers to generate spendable XRP without supplying the necessary funds, leading developers to release an emergency software update.

A security report published Friday revealed that the flaw could have enabled malicious actors to create substantial amounts of XRP without paying for them, potentially violating the cryptocurrency’s fixed-supply limit. The vulnerability was believed to have existed since 2015.

Researcher Cayden Liao and Veria AI discovered the issue and reported it privately on Sept. 22. Engineers at RippleX, Ripple’s development division, successfully reproduced the attack on an isolated server and verified that the newly generated XRP could be spent in subsequent transactions.

RippleX said it had found no evidence that the vulnerability had been exploited on any public network.

The XRP Ledger launched in 2012 with a total supply of 100 billion XRP. Its protocol is designed to prevent the creation of additional tokens. However, the discovered vulnerability could potentially have allowed attackers to generate XRP from nothing and sell it on cryptocurrency exchanges, undermining the supply limit relied upon by institutions using the network.

The exploit took advantage of the XRP Ledger’s built-in decentralized exchange, where users can place offers to trade one token for another.

In theory, an attacker could create hundreds of accounts, each offering a small quantity of another token in exchange for an unusually large amount of XRP. The attacker could then submit a single payment that executed all the offers simultaneously.

Because the total amount of XRP owed would exceed what the software could accurately calculate, the system could incorrectly process the transaction. The selling accounts would receive their full XRP payments, while the buying account would be charged almost nothing, effectively creating new XRP that had not previously existed.

Although the XRP Ledger checks after every transaction to ensure that no additional XRP has been created, the verification process could have relied on the incorrectly calculated total and failed to detect the extra tokens.

Another safeguard limiting the amount of XRP an individual account could receive would not necessarily have prevented the exploit. By distributing the newly generated tokens across hundreds of accounts, an attacker could have avoided triggering that restriction.

The researchers said the attack required only a few hundred XRP to establish the necessary accounts, most of which could later be recovered, along with transaction fees.

Developers released a fix through version 3.4.1 of xrpld, the XRP Ledger’s server software, on Sept. 25. The update was issued without publicly disclosing the specific vulnerability it addressed.

The discovery adds to a series of previously undetected cryptocurrency security flaws identified with assistance from artificial intelligence since July. Other incidents include a Coldcard wallet vulnerability associated with the theft of at least 1,367 BTC and security issues that prompted Core Lightning to advise Bitcoin node operators to disconnect.

About The Author