Dapplick
Dapplick

Web3 news about what gets built and used

Sunday, 11 October 2026
Home>Security>XRP Ledger Fixes Major Security Flaw Allowing Crea…
Security

XRP Ledger Fixes Major Security Flaw Allowing Creation of New XRP

·2 min read

Written with artificial intelligence.

XRP Ledger Fixes Major Security Flaw Allowing Creation of New XRP

A critical vulnerability in the XRP Ledger could have allowed the creation of new XRP without funding, potentially undermining the token's fixed supply. The issue, discovered by researcher Cayden Liao, has been patched in the latest software update.

Overview of the Vulnerability

A flaw in the XRP Ledger’s payment system may have enabled attackers to generate substantial amounts of new XRP without any cost, violating the token's fixed supply principle. This security risk was outlined in a report released by researchers on Friday.

Details of the Exploit

This bug, traced back to 2015, was identified by researcher Cayden Liao in collaboration with Veria AI and reported internally on September 22. RippleX engineers were able to replicate the attack on a separate server, confirming that the generated XRP could be utilized in subsequent transactions. Fortunately, RippleX stated that there is no evidence the flaw was exploited on any public network.

Implications of the Flaw

The XRP Ledger, which launched with a cap of 100 billion XRP in 2012, is designed to prevent the creation of additional tokens. However, the discovered vulnerability could have allowed an attacker to produce XRP from nothing and sell it on exchanges, which would compromise the supply cap that institutions depend upon.

XRP Ledger Fixes Major Security Flaw Allowing Creation of New XRP
Image generated with AI

How the Exploit Worked

The exploit involved leveraging the ledger’s exchange features. An attacker could create numerous accounts, each offering a minor token in exchange for a disproportionately large amount of XRP. By sending a single payment that accepted all offers simultaneously, the total XRP owed would exceed the system's counting capacity, allowing the attacker to receive an excessive amount of XRP with minimal cost. The existing checks in place would not flag this exploit due to the flawed counting method.

Resolution

Developers addressed this issue by releasing an update, xrpld 3.4.1, on September 25, although they did not specify the nature of the fix at that time. This incident is part of a broader trend of previously undetected security vulnerabilities in crypto systems being uncovered with the help of artificial intelligence since July.

SecurityXrpLedgerExploitRipple
← Back to homepage