HomeMarket NewsXRP

XRP Ledger Bug Could Have Allowed Hackers to Create Unlimited XRP, Developers Reveal

XRP Ledger Bug Could Have Allowed Hackers to Create Unlimited XRP, Developers Reveal

In Brief:

  • XRP Ledger developers disclosed a critical payment engine vulnerability that could have allowed attackers to create unauthorized, spendable XRP tokens.


  • A security researcher uncovered an integer overflow flaw dating back to 2015, exposing weaknesses in the network’s supply protection mechanisms.


  • Developers released xrpld 3.4.1 through an emergency upgrade, bypassing standard amendment procedures, with no evidence of exploitation on public networks.


     


A critical XRP Ledger vulnerability could have allowed attackers to generate unauthorized XRP tokens and transfer them through ordinary accounts. XRPL developers disclosed the security flaw in an October 9 report detailing vulnerabilities addressed through the emergency xrpld 3.4.1 release.


According to the disclosure, the payment engine contained an integer overflow error that could bypass safeguards protecting XRP’s supply. Attackers could potentially exploit the weakness through a single transaction, creating spendable XRP beyond the network’s intended supply limits.


The vulnerability affected xrpld version 3.4.0 and earlier releases, raising concerns about a flaw embedded in the protocol for years. Developers also identified a separate Batch inner transaction wrapper validation error, which the September 25 emergency update addressed.


Also Read: Avalanche Founder Warns AI Could Uncover Hidden XRP Ledger Vulnerabilities


XRP Ledger Payment Engine Flaw Exposed Major Supply Risk

A security researcher discovered the payment engine vulnerability and submitted findings through the XRPL Bug Bounty program on September 22. The researcher demonstrated how specially constructed trading offers could manipulate calculations when a payment consumed multiple orders from the ledger.


Under normal conditions, the payment engine calculates the total XRP required to complete transactions involving several order book offers. Yet the vulnerability allowed certain calculations to exceed their permitted integer limits, causing the resulting value to reset unexpectedly.


Consequently, sellers could receive their full XRP payments while buyers incurred charges significantly smaller than the actual transaction amounts. This difference effectively created unauthorized XRP, which attackers could transfer, trade, or deposit into cryptocurrency exchange accounts.


Investigators also discovered that the ledger’s built-in supply protection could fail because its calculations experienced the same overflow. Further examination traced the vulnerability to payment engine code introduced in 2015, leaving the weakness undiscovered for approximately eleven years.


Emergency XRPL Upgrade Bypassed Standard Amendment Process

Developers addressed the overflow vulnerability through xrpld 3.4.1, which launched on September 25 to protect the network against potential exploitation. Given the severity, developers implemented the correction without following the XRP Ledger’s established amendment approval process.


This marked the first deliberate transaction-processing change outside that process since the amendment system emerged more than a decade ago. Importantly, investigators found no evidence that attackers exploited the payment engine vulnerability on any public XRP Ledger network.


The correction takes effect immediately when server operators install xrpld 3.4.1, eliminating the identified overflow vulnerability. Developers urged operators to upgrade their servers to maintain network synchronization and ensure the corrected transaction processing rules apply.


The October 9 disclosure documented both vulnerabilities and explained the emergency measures developers introduced to protect XRP Ledger operations.


Also Read: US Treasury Targets Another $1 Billion in Iran-Linked Crypto Under Trump Crackdown