XRP Ledger bug could have minted spendable XRP, RippleX says no public network abuse found

XRP Ledger bug could have minted spendable XRP, RippleX says no public network abuse found

N
News Editor
2026-10-10 07:06:29
A security report released Friday said a flaw in the XRP Ledger payment system could, in theory, have allowed attackers to create large amounts of new XRP at almost no cost, breaking the token’s fixed-supply design. The issue was traced back to 2015, according to the report, and was discovered by researcher Cayden Liao and Veria AI, who privately disclosed it on Sept. 22. RippleX engineers later reproduced the exploit on an isolated server and confirmed that the newly created XRP could be spent in subsequent transactions. RippleX said it found no evidence that the bug had been exploited on any public network. The report said the attack path involved the ledger’s built-in exchange, where accounts post offers to swap one token for another. By spreading trades across hundreds of accounts, an attacker could allegedly trigger a counting error large enough for seller accounts to receive full XRP payouts while buyer accounts were barely debited. Developers shipped a fix in xrpld 3.4.1 on Sept. 25 without publicly detailing the issue at the time. The case adds to a recent run of long-hidden crypto vulnerabilities that have surfaced with AI-assisted research.

A security report released Friday said a flaw in the XRP Ledger payment system could have let attackers create large amounts of new XRP at almost no cost, undermining the token’s fixed-supply design.

XRP Ledger bug could have minted spendable XRP, RippleX says no public network abuse found 2

The bug was believed to date back to 2015. It was identified by researcher Cayden Liao and Veria AI, then privately reported on Sept. 22. Engineers at Ripple’s development arm, RippleX, reproduced the attack on an isolated server and confirmed that the newly created XRP could be spent in later transactions.

RippleX said it found no evidence that the flaw had been exploited on any public network.

A direct challenge to XRP’s fixed-supply model

All 100 billion XRP were created when the ledger launched in 2012, and the software was designed so no additional XRP could ever be issued. According to the report, this bug could have allowed an attacker to fabricate XRP and sell it on exchanges, weakening the supply cap that institutions and token holders rely on.

The attack path centered on the ledger’s built-in exchange, where accounts can post offers to swap one token for another.

In the scenario described by the researchers, an attacker could open hundreds of accounts and have each one offer a tiny amount of tokens in exchange for an abnormally large amount of XRP. The attacker could then send a single payment that consumed all of those offers at once.

The XRP owed in that transaction would be so large that the software would fail to count it correctly. As a result, the attacker’s seller accounts would receive the full payout, while the buyer accounts would barely be debited. That would leave the attacker with XRP that did not previously exist.

XRP Ledger bug could have minted spendable XRP, RippleX says no public network abuse found 3

Why the ledger’s checks did not stop it

The XRP Ledger runs a check after each transaction to confirm that no new XRP has appeared. The report said that check relied on the same miscalculated total, which allowed the issue to slip through.

A separate limit on how much XRP a single account can receive would not have been triggered either, because the attack distributed the XRP across hundreds of accounts.

The researchers said the method required only a few hundred XRP to create those accounts. Most of that amount could be recovered, with the remaining cost coming from transaction fees.

Fix shipped in xrpld 3.4.1 on Sept. 25

Developers delivered a fix in the ledger server software xrpld 3.4.1 on Sept. 25, though they did not disclose at the time what issue had been patched.

The report also placed the episode in a broader security context. Since July, a series of long-hidden crypto vulnerabilities have been uncovered with AI assistance, including a Coldcard wallet flaw tied to the theft of at least 1,367 BTC and another set of bugs that led Core Lightning to ask Bitcoin node operators to disconnect.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.