MCAP$2.80T-2.23%
BTC$82,700+0.23%ETH$2,496+0.00%SOL$110.07-0.50%XRP$1.41+0.69%
GOLD$4,216+1.43%
OIL$104.72+0.42%
STOCKTSLA$382.70+2.05%STOCKNVDA$229.28-0.52%STOCKAAPL$336.64-1.11%STOCKCOIN$179.39+4.30%STOCKMSTR$154.34+1.90%
BTC DOM59.1%
FEAR & GREED64Greed
Updated
Breaking crypto news, seconds after it happens

Whale alerts, listings and market-moving headlines on Telegram.

Join Telegram
Just In

XRP Ledger Patches Decade-Old Bug That Threatened Token Supply

RippleX patched a flaw dating back to 2015 that could have allowed attackers to create and spend new XRP, violating the token's 100 billion fixed supply.

XRP Ledger Patches Decade-Old Bug That Threatened Token Supply
Image: BullishMarketCap

Developers at RippleX patched a decade-old vulnerability in the XRP Ledger that could have allowed an attacker to create and spend new tokens without funding them, according to a security report published by CoinDesk.

The flaw, dating back to 2015, was discovered by researcher Cayden Liao and Veria AI, and internally reported on Sept. 22. Engineers at RippleX reproduced the attack on a standalone server and confirmed that newly created XRP could be spent in subsequent transactions, violating the cryptocurrency's fixed supply cap of 100 billion tokens.

Get whale alerts first

Instant Telegram notifications for large on-chain moves.

Join Telegram

Exchange Flaw and Exploitation Method

The vulnerability exploited a counting error within the ledger's built-in exchange, where accounts post offers to trade tokens. According to the report, an attacker could open hundreds of accounts, place tiny token offers in exchange for unusually large amounts of XRP, and execute a single payment that bought every offer simultaneously.

The software miscounted the total XRP owed, allowing selling accounts to be paid in full while the buying account was charged almost negligible amounts. This process left the attacker with spendable XRP that had never existed previously. The ledger's post-transaction verification check and single-account receive limits failed to catch the anomaly because the totals and balances were miscalculated and distributed across numerous accounts.

Emergency Software Release

RippleX stated that it found no evidence the vulnerability was exploited on any public network. Developers shipped the fix globally in the xrpld 3.4.1 server software release on Sept. 25 without initially disclosing the specific malfunction.

Key facts

  • A vulnerability dating to 2015 could have allowed attackers to create and spend new XRP from nothing.
  • The flaw was discovered by researcher Cayden Liao and Veria AI, and reported on Sept. 22.
  • RippleX engineers reproduced the attack and confirmed the newly created tokens could be spent.
  • The fix was deployed in the xrpld 3.4.1 software release on Sept. 25.
  • RippleX found no evidence of exploitation on public networks.
$XRP#XRPLedger#Ripple#CryptoSecurity

Source: coindesk.com

This article is for information only and is not investment advice. BullishMarketCap news is produced with AI assistance from public sources and reviewed by our editors; see our editorial policy. Spotted an error? Tell us.

More Just In

View all →