#xrp账本修复可增发xrp的漏洞
【Veteran Crypto Watch】XRP’s most dangerous vulnerability exposed! Attackers may have been able to create spendable XRP out of thin air; an urgent fix has been deployed
🔴 1. What exactly was the vulnerability?
The issue was in the XRP Ledger’s payment engine. Normally, when users trade through the order book, the system calculates how much the buyer needs to pay. The vulnerability involved integer overflow: when a payment required totaling a large number of order quotes, the result could exceed the integer type’s limit, causing the amount to “wrap around” to a very small value.
As a result, sellers could receive the XRP they were each owed, while the buyer might be charged far less than the amount due.
The difference would effectively amount to new XRP created out of thin air.
More seriously, the existing security check designed to prevent XRP from being created out of thin air also used a calculation method vulnerable to overflow, meaning it might fail to detect the anomaly.
🔴 2. The attack could have been very low-cost
According to the official disclosure, an attacker would need to carefully craft hundreds of abnormal orders and then submit a specific payment transaction. The attack would not require much initial capital; the main costs would be account and order reserve requirements, plus transaction fees.
🔴 3. Has the vulnerability been fixed?
Yes.
• September 22, 2026: Researchers reported the issue through the bug bounty program.
• September 23: The fix was merged into xrpld 3.4.1.
• September 25: The emergency 3.4.1 release was published, and validators upgraded quickly.
• October 9: XRPL published a detailed vulnerability disclosure report.
The official statement says there is currently no evidence that the vulnerability was exploited on the public network.
$XRP $BTC $MAGIC
【Veteran Crypto Watch】XRP’s most dangerous vulnerability exposed! Attackers may have been able to create spendable XRP out of thin air; an urgent fix has been deployed
🔴 1. What exactly was the vulnerability?
The issue was in the XRP Ledger’s payment engine. Normally, when users trade through the order book, the system calculates how much the buyer needs to pay. The vulnerability involved integer overflow: when a payment required totaling a large number of order quotes, the result could exceed the integer type’s limit, causing the amount to “wrap around” to a very small value.
As a result, sellers could receive the XRP they were each owed, while the buyer might be charged far less than the amount due.
The difference would effectively amount to new XRP created out of thin air.
More seriously, the existing security check designed to prevent XRP from being created out of thin air also used a calculation method vulnerable to overflow, meaning it might fail to detect the anomaly.
🔴 2. The attack could have been very low-cost
According to the official disclosure, an attacker would need to carefully craft hundreds of abnormal orders and then submit a specific payment transaction. The attack would not require much initial capital; the main costs would be account and order reserve requirements, plus transaction fees.
🔴 3. Has the vulnerability been fixed?
Yes.
• September 22, 2026: Researchers reported the issue through the bug bounty program.
• September 23: The fix was merged into xrpld 3.4.1.
• September 25: The emergency 3.4.1 release was published, and validators upgraded quickly.
• October 9: XRPL published a detailed vulnerability disclosure report.
The official statement says there is currently no evidence that the vulnerability was exploited on the public network.
$XRP $BTC $MAGIC