CoinDesk·4 min read·hard

XRP Ledger patched decade-old bug that could create billions of dollars in XRP from nothing

S
Shaurya Malwa
XRP Ledger patched decade-old bug that could create billions of dollars in XRP from nothing
✦AI Summary

The XRP Ledger recently patched a decade-old security vulnerability that could have allowed attackers to create XRP tokens out of thin air. Researchers discovered the flaw, which exploited the ledger's internal exchange mechanism, though there is no evidence it was ever exploited on the public network.

Why it matters

This incident underscores the critical importance of security audits in blockchain infrastructure, especially when dealing with fixed-supply digital assets.

✦Dive DeeperCreate a free account to unlock

The bug, believed to date to 2015, was found by researcher Cayden Liao and Veria AI and internally reported on Sept. 22. Engineers at RippleX, Ripple’s developer arm, reproduced the attack on a standalone server and confirmed the newly created XRP could be spent in a later transaction.

RippleX said it found no evidence the flaw was exploited on any public network.

All 100 billion XRP were created when the ledger launched in 2012, and its software is built so no more can ever be added. But the security vulnerability could have allowed an attacker to create XRP from nothing and sell it on exchanges, undercutting a supply cap that institutions using the network rely on.

The attack worked through the ledger’s built-in exchange, where accounts post offers to swap one token for another.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologycryptobusiness
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in