A security report released Friday said a flaw in the XRP Ledger payment system could have let attackers create large amounts of new XRP at almost no cost, undermining the token’s fixed-supply design.

The bug was believed to date back to 2015. It was identified by researcher Cayden Liao and Veria AI, then privately reported on Sept. 22. Engineers at Ripple’s development arm, RippleX, reproduced the attack on an isolated server and confirmed that the newly created XRP could be spent in later transactions.
RippleX said it found no evidence that the flaw had been exploited on any public network.
A direct challenge to XRP’s fixed-supply model
All 100 billion XRP were created when the ledger launched in 2012, and the software was designed so no additional XRP could ever be issued. According to the report, this bug could have allowed an attacker to fabricate XRP and sell it on exchanges, weakening the supply cap that institutions and token holders rely on.
The attack path centered on the ledger’s built-in exchange, where accounts can post offers to swap one token for another.
In the scenario described by the researchers, an attacker could open hundreds of accounts and have each one offer a tiny amount of tokens in exchange for an abnormally large amount of XRP. The attacker could then send a single payment that consumed all of those offers at once.
The XRP owed in that transaction would be so large that the software would fail to count it correctly. As a result, the attacker’s seller accounts would receive the full payout, while the buyer accounts would barely be debited. That would leave the attacker with XRP that did not previously exist.

Why the ledger’s checks did not stop it
The XRP Ledger runs a check after each transaction to confirm that no new XRP has appeared. The report said that check relied on the same miscalculated total, which allowed the issue to slip through.
A separate limit on how much XRP a single account can receive would not have been triggered either, because the attack distributed the XRP across hundreds of accounts.
The researchers said the method required only a few hundred XRP to create those accounts. Most of that amount could be recovered, with the remaining cost coming from transaction fees.
Fix shipped in xrpld 3.4.1 on Sept. 25
Developers delivered a fix in the ledger server software xrpld 3.4.1 on Sept. 25, though they did not disclose at the time what issue had been patched.
The report also placed the episode in a broader security context. Since July, a series of long-hidden crypto vulnerabilities have been uncovered with AI assistance, including a Coldcard wallet flaw tied to the theft of at least 1,367 BTC and another set of bugs that led Core Lightning to ask Bitcoin node operators to disconnect.

