【One payment nearly printed $XRP out of thin air 😱🖨️】

Join Mr. X’s fan group chat from the homepage 🔥

One payment could, in theory, create $XRP out of thin air. This isn’t a movie plot—it’s something that was just disclosed last week. The ledger’s rules hard-code the total supply at 100 billion coins. That safeguard nearly got overturned by a single counting error. 🔓

The problem lay in the ledger’s built-in exchange system. The attack was simple, but devastating. First, open hundreds of accounts, each with a tiny sell order. The items being sold were practically worthless, but the amount of XRP asked for was absurdly high. Then one final payment would sweep up all the sell orders at once. 💥

The problem was that the numbers didn’t add up. When the total overflowed, the software recorded the wrong amount. The sellers received the full payment, while the buyer was charged almost nothing. The extra XRP created out of thin air ended up in their pockets. There was supposed to be a check after the transaction, but it relied on that same incorrect figure. The receiving limit didn’t stop it either, because the coins were split up across many accounts. 📊

The cost was actually low. Opening accounts required only a few hundred XRP, most of which could be recovered. The discoverer was Cayden Liao, who found it together with the AI team at Veria. The team reported it internally on September 22. RippleX reproduced the attack, and the newly created coins could indeed be spent. 🧪

The fix quietly went live on September 25, in version xrpld 3.4.1. The team didn’t say at the time what had been fixed. RippleX said there was no evidence of exploitation on the public network. My personal take: just because it wasn’t exploited doesn’t mean nobody tried. Institutions trust that the total supply is fixed; if that guarantee wavers, everything comes crashing down. 🏛️

These kinds of old vulnerabilities have been cropping up in clusters lately. Since July, the Coldcard vulnerability has led to major fallout. At least 1,367 bitcoins have been stolen. Bitcoin nodes have also been pushed offline. AI is helping find bugs, and both sides of the security battle are picking up speed. 🔍

📌 A fixed total supply is the foundation of trust. If the foundation crumbles, even a high price is worthless.

Do you think these invisible vulnerabilities should be fixed before they’re disclosed?