#xrpledgerpatchesxrpcreationbug
๐จ XRP Ledger Patches XRP Creation Bug ๐ก๏ธ
๐ง The XRPL disclosed on Oct 9 that it fixed a critical, decade-old bug in its payment engine. The flaw could have let an attacker create spendable XRP beyond the 100B supply cap. ๐ฑ
๐ง How did the bug work?
๐น A payment sweeping through hundreds of order book offers could trigger an integer overflow in the XRP calculation ๐ข
๐น The total wrapped to a much smaller number, while sellers still received the full amounts ๐
๐น The difference could become newly created XRP ๐ช
๐น Exploiting it required hundreds of deliberately mispriced offers, plus reserves of a few hundred XRP ๐งฉ
๐ Timeline
๐ก Sep 22: Researcher Cayden Liao and Veria AI report the bug via the bug bounty program ๐ต๏ธ
๐ข Sep 25: Fix released in xrpld 3.4.1, with over 80% of default UNL validators upgraded within 24 hours โก
๐ต Oct 9: Public disclosure โ
โ Key facts
๐ธ RippleX reproduced the exploit on a standalone server, but found no evidence of exploitation on the mainnet ๐
๐ธ The patch shipped as an emergency release outside the normal amendment vote, so the flaw wasnโt left exposed during a public voting period ๐ณ๏ธ
๐ธ A second, lower-severity bug in the Batch feature was also fixed. Batch wasnโt active on the mainnet when it was found ๐งฑ
๐ก Takeaway: The bug bounty process worked: reported, reproduced and patched in just 3 days. ๐ Node operators should make sure they run xrpld 3.4.1 or later. ๐ฅ๏ธ
๐ฌ Does this make you more or less confident in XRPLโs security? ๐ค๐
#XRP #XRPL #Ripple #RippleX
Not financial advice. DYOR. โ ๏ธ$XRP
๐จ XRP Ledger Patches XRP Creation Bug ๐ก๏ธ
๐ง The XRPL disclosed on Oct 9 that it fixed a critical, decade-old bug in its payment engine. The flaw could have let an attacker create spendable XRP beyond the 100B supply cap. ๐ฑ
๐ง How did the bug work?
๐น A payment sweeping through hundreds of order book offers could trigger an integer overflow in the XRP calculation ๐ข
๐น The total wrapped to a much smaller number, while sellers still received the full amounts ๐
๐น The difference could become newly created XRP ๐ช
๐น Exploiting it required hundreds of deliberately mispriced offers, plus reserves of a few hundred XRP ๐งฉ
๐ Timeline
๐ก Sep 22: Researcher Cayden Liao and Veria AI report the bug via the bug bounty program ๐ต๏ธ
๐ข Sep 25: Fix released in xrpld 3.4.1, with over 80% of default UNL validators upgraded within 24 hours โก
๐ต Oct 9: Public disclosure โ
โ Key facts
๐ธ RippleX reproduced the exploit on a standalone server, but found no evidence of exploitation on the mainnet ๐
๐ธ The patch shipped as an emergency release outside the normal amendment vote, so the flaw wasnโt left exposed during a public voting period ๐ณ๏ธ
๐ธ A second, lower-severity bug in the Batch feature was also fixed. Batch wasnโt active on the mainnet when it was found ๐งฑ
๐ก Takeaway: The bug bounty process worked: reported, reproduced and patched in just 3 days. ๐ Node operators should make sure they run xrpld 3.4.1 or later. ๐ฅ๏ธ
๐ฌ Does this make you more or less confident in XRPLโs security? ๐ค๐
#XRP #XRPL #Ripple #RippleX
Not financial advice. DYOR. โ ๏ธ$XRP