XRP Ledger has patched a payment-system vulnerability that may date back to 2015, according to a ChainCatcher report. The flaw could have let an attacker use a specially crafted payment transaction to bypass limits in the system’s token-conversion calculations, potentially creating and spending large amounts of XRP and undermining the network’s 100 billion XRP supply cap. The disclosed attack path involved creating hundreds of accounts, posting offers to exchange small amounts of tokens for large quantities of XRP, and then executing them in a single payment. Because of a defect in how the software calculated transaction totals, seller accounts could receive the full XRP amount while buyer accounts paid little or almost nothing. Researchers Cayden Liao and Veria AI reported the issue on Sept. 22. RippleX later reproduced the attack and confirmed that the generated XRP could be used in subsequent transactions. RippleX said it has found no evidence that the vulnerability was exploited on any public network. The development team released xrpld version 3.4.1 on Sept. 25 to fix the issue.
XRP Ledger has patched a payment-system vulnerability that may date back to 2015, according to ChainCatcher. The flaw could have allowed an attacker to use a specially crafted payment transaction to bypass limits in the system’s token-conversion calculations, create and spend large amounts of XRP, and break the mechanism that caps XRP supply at 100 billion tokens.
The disclosed attack used many accounts and manipulated offers
According to the disclosure, an attacker could create hundreds of accounts and have them place offers to exchange small amounts of tokens for huge amounts of XRP, then match those offers in a single payment. Because the software had a defect in calculating the total amount of the transaction, seller accounts could receive the full XRP amount while buyer accounts paid little or almost nothing in return.
Researchers reported the issue on Sept. 22
Researchers Cayden Liao and Veria AI reported the vulnerability on Sept. 22. RippleX later reproduced the attack and confirmed that the generated XRP could be used in subsequent transactions.
xrpld 3.4.1 was released on Sept. 25
RippleX said there is currently no evidence that the flaw was ever exploited on any public network. The development team released xrpld version 3.4.1 on Sept. 25 to address the issue.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.