XRP Ledger Fixes Major Security Flaw Allowing Creation of New XRP
Written with artificial intelligence.

A critical vulnerability in the XRP Ledger could have allowed the creation of new XRP without funding, potentially undermining the token's fixed supply. The issue, discovered by researcher Cayden Liao, has been patched in the latest software update.
Overview of the Vulnerability
A flaw in the XRP Ledger’s payment system may have enabled attackers to generate substantial amounts of new XRP without any cost, violating the token's fixed supply principle. This security risk was outlined in a report released by researchers on Friday.
Details of the Exploit
This bug, traced back to 2015, was identified by researcher Cayden Liao in collaboration with Veria AI and reported internally on September 22. RippleX engineers were able to replicate the attack on a separate server, confirming that the generated XRP could be utilized in subsequent transactions. Fortunately, RippleX stated that there is no evidence the flaw was exploited on any public network.
Implications of the Flaw
The XRP Ledger, which launched with a cap of 100 billion XRP in 2012, is designed to prevent the creation of additional tokens. However, the discovered vulnerability could have allowed an attacker to produce XRP from nothing and sell it on exchanges, which would compromise the supply cap that institutions depend upon.
How the Exploit Worked
The exploit involved leveraging the ledger’s exchange features. An attacker could create numerous accounts, each offering a minor token in exchange for a disproportionately large amount of XRP. By sending a single payment that accepted all offers simultaneously, the total XRP owed would exceed the system's counting capacity, allowing the attacker to receive an excessive amount of XRP with minimal cost. The existing checks in place would not flag this exploit due to the flawed counting method.
Resolution
Developers addressed this issue by releasing an update, xrpld 3.4.1, on September 25, although they did not specify the nature of the fix at that time. This incident is part of a broader trend of previously undetected security vulnerabilities in crypto systems being uncovered with the help of artificial intelligence since July.
