A bug in the XRP Ledger's payment engine let one payment mint new XRP from nothing. It sat in the code for about a decade, and the fix went live before anyone could read it.

The engine summed what a buyer owed across offers with a plain 64-bit counter. A few hundred crafted offers, each asking for a huge amount of XRP, pushed the total past the limit and it wrapped around to almost zero. Sellers got paid in full, the buyer paid next to nothing, and the "no XRP created" check used the same counter, so it saw nothing.

By our math, that counter tops out at about 9.2 trillion XRP, roughly 92 times the 100B supply. No account may hold more than the whole supply, so the attack needed at least 93 receiving accounts.

Cayden Liao and Veria AI reported it through the XRPL bug bounty on Sept 22. xrpld 3.4.1 shipped Sept 25 with its source held back, and over 80% of default UNL validators ran it that day. It skipped the amendment vote, a first for a transaction-processing fix in over ten years. RippleX found no sign it was ever used on a public network.

About ten years in the code. Three days to patch.

$XRP
#XRP #CryptoSecurity
NFA. DYOR.