Came across this on CoinDesk / the official XRPL blog: an integer overflow had been buried in the ledger’s payment engine since around 2015. It was publicly disclosed only after the patch was released.
Attack path: post hundreds of extreme offers, then wipe them out all at once with a single payment—the engine paid sellers the full amount per offer, but charged the buyer only a tiny amount after the overflow wrapped around. That effectively created spendable XRP out of thin air, breaking the roughly 100-billion total supply cap. The on-chain “no new issuance” check used the same addition, so it was bypassed too.
Key details: Cayden Liao / Veria AI reported it through the bug bounty program on 9/22; RippleX reproduced it locally and confirmed that newly minted XRP could be spent. No exploitation was found on the public network. The patch was included in xrpld 3.4.1 on 9/25—and because the issue was so severe, it bypassed the usual two-week amendment window and took effect with a node upgrade. More than 80% of the default UNL had upgraded by the day of release. The detailed report wasn’t published until 10/9.
On a fixed-supply chain, “extra coins” are the nightmare scenario. This time, the bug bounty report and emergency patch plugged a decade-old hole before it could be exploited.
$XRP #XRPL #Security
Attack path: post hundreds of extreme offers, then wipe them out all at once with a single payment—the engine paid sellers the full amount per offer, but charged the buyer only a tiny amount after the overflow wrapped around. That effectively created spendable XRP out of thin air, breaking the roughly 100-billion total supply cap. The on-chain “no new issuance” check used the same addition, so it was bypassed too.
Key details: Cayden Liao / Veria AI reported it through the bug bounty program on 9/22; RippleX reproduced it locally and confirmed that newly minted XRP could be spent. No exploitation was found on the public network. The patch was included in xrpld 3.4.1 on 9/25—and because the issue was so severe, it bypassed the usual two-week amendment window and took effect with a node upgrade. More than 80% of the default UNL had upgraded by the day of release. The detailed report wasn’t published until 10/9.
On a fixed-supply chain, “extra coins” are the nightmare scenario. This time, the bug bounty report and emergency patch plugged a decade-old hole before it could be exploited.
$XRP #XRPL #Security