Dapplick
Dapplick

Web3 news about what gets built and used

Sunday, 11 October 2026
Home>Security>Critical Security Flaw in XRP Ledger Nearly Led to…
Security

Critical Security Flaw in XRP Ledger Nearly Led to Token Flood

·1 min read

Written with artificial intelligence.

Critical Security Flaw in XRP Ledger Nearly Led to Token Flood

A significant vulnerability in the XRP Ledger could have allowed attackers to generate unlimited XRP tokens. Ripple took urgent measures to address this issue, which had remained undetected for nearly eleven years.

Overview of the Security Vulnerability

A severe security flaw in the XRP Ledger posed a risk of catastrophic exploitation, enabling attackers to create and sell unlimited amounts of XRP. This vulnerability, discovered by security researcher Cayden Liao and Veria AI, reportedly existed since 2015 and was revealed in a security report published on September 22.

Nature of the Flaw

The issue was located in the payment processing mechanism of the XRP network and could have been exploited through the integrated marketplace. An attacker would have needed to create several hundred accounts, offering large amounts of XRP in exchange for small quantities of other tokens. A well-crafted payment could have facilitated the generation of new XRP without providing the necessary countervalue.

The root of the problem was a miscalculation in payment amounts that allowed an internal counter to exceed its maximum limit. Consequently, sellers could receive their full XRP amounts, while buyers would be charged only a fraction, bypassing an internal security check that operated on the same flawed calculation.

Critical Security Flaw in XRP Ledger Nearly Led to Token Flood
Image generated with AI

Ripple's Response

To mitigate the potential threat, RippleX released software version 3.4.1 on September 25, taking the rare step of activating the fix immediately, bypassing the usual voting process that requires over 80% support from trusted validators over two weeks. RippleX acknowledged that this exception was necessary due to the critical nature of the security risk, as a standard voting process would have left the vulnerability exposed for weeks.

Moving forward, RippleX has stated that while future changes will adhere to the regular voting protocol, exceptions will only be made for severe security issues.

SecurityXrpRipple
← Back to homepage