A long-standing security vulnerability in the XRP Ledger that could have allowed the creation of new XRP tokens has been patched by developers. The flaw, which is believed to date back to 2015, threatened to violate the cryptocurrency's fixed supply cap of 100 billion tokens.
Researcher Cayden Liao and Veria AI discovered the issue and internally reported it on September 22. Ripple's developer arm, RippleX, successfully reproduced the attack on a standalone server and confirmed that newly generated XRP could subsequently be spent.
According to the security report, the vulnerability leveraged a counting error within the ledger's built-in exchange, where accounts place offers to swap tokens. An attacker could theoretically utilize hundreds of accounts offering small amounts of a token for large quantities of XRP. By executing a single payment that purchased all offers simultaneously, the software would miscalculate the total XRP owed, paying the selling accounts in full while charging the buying account almost nothing.
Post-transaction verification checks and single-account receiving limits failed to catch the discrepancy because the calculations relied on the same miscounted totals and the funds were distributed across multiple accounts. The exploit method required only a minimal amount of XRP to establish the accounts, along with standard transaction fees.
RippleX stated that there was no evidence of the vulnerability being exploited on any public network. Engineers addressed the issue on September 25 with the release of xrpld server software version 3.4.1, initially deploying the fix without publicly disclosing the specific problem it resolved.


