XRP Ledger has patched a payment-system flaw that may date back to 2015, according to BlockBeats. The issue could have let an attacker use a specially crafted payment transaction to bypass limits in the system’s token-conversion calculations, potentially creating and spending large amounts of XRP and undermining the network’s 100 billion XRP supply cap. The disclosed attack path involved creating hundreds of accounts, posting offers to exchange tiny amounts of tokens for massive amounts of XRP, and then executing them together in a single payment. Because of a defect in how the software calculated aggregate transaction amounts, seller accounts could receive the full XRP while buyer accounts paid little to almost nothing. Researchers Cayden Liao and Veria AI reported the vulnerability on Sept. 22. RippleX later reproduced the exploit and confirmed that the XRP generated through it could be used in subsequent transactions. RippleX said it has found no evidence that the flaw was exploited on any public network. The fix was released on Sept. 25 in xrpld version 3.4.1.
XRP Ledger has fixed a payment-system vulnerability that may trace back to 2015, according to BlockBeats on Oct. 10. The flaw could have allowed an attacker to use a specially crafted payment transaction to bypass limits in the ledger’s token-conversion amount calculations, making it possible to create and spend large amounts of XRP and break the mechanism that caps total XRP supply at 100 billion tokens.
Based on the disclosed details, an attacker could create hundreds of accounts and have those accounts place offers to swap small amounts of tokens for huge amounts of XRP. The attacker could then execute those offers in a single payment. Because the software contained an error in calculating the total transaction amount, seller accounts could receive the full XRP amount while buyer accounts paid little to almost none of the corresponding value.
Researchers Cayden Liao and Veria AI reported the flaw on Sept. 22. RippleX later reproduced the attack and confirmed that XRP generated in this way could be used in subsequent transactions.
RippleX said there is currently no evidence that the vulnerability was ever exploited on any public network. The development team released a fix in xrpld version 3.4.1 on Sept. 25.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.