#xrp账本修复可增发xrp的漏洞 $XRP This time, the network narrowly avoided coins being minted out of thin air. But what surprised me most was how the developers patched the vulnerability.
The vulnerability had been hidden in the XRP Ledger’s payment engine since 2015. By exploiting an arithmetic overflow, an attacker could theoretically create new coins out of thin air with only a few hundred XRP in upfront costs.
Fortunately, after investigating, the developers said they found no evidence that the vulnerability had been exploited on the public network.
But what happened next is the really interesting part.
Normally,
major protocol changes to the XRPL have to go through the amendment process: validators must reach over 80% consensus, and that consensus must be maintained for two weeks before the change takes effect.
But this time, the developers took a different approach. They upgraded the node software to version 3.4.1, which enabled the fix.
According to the official report, this was the first time in the more than ten years since the amendment process was introduced that this kind of emergency fix had been used.
The reason is easy enough to understand.
Once a vulnerability is made public, hackers may start looking for ways to exploit it. Having to wait two weeks for a vote would leave the network exposed to risk during that time.
So the fix was given the highest priority. On the day it was released, over 80% of the nodes on the default validator list had already upgraded—even though the source code for the fix had not yet been made public.
That’s the most important thing to discuss about this whole incident.
People often emphasize blockchain decentralization, transparency, and on-chain governance. But when a serious vulnerability could threaten the entire network’s supply, a trade-off has to be made between security and the usual governance process.
Regular XRP holders don’t need to change wallets because of this vulnerability. Those running nodes should make sure their software has been upgraded.
The crypto world talks endlessly about how important decentralization is. But if a vulnerability could let someone mint coins out of thin air, would you rather wait two weeks for the process to run its course, or support plugging the hole first?
$XRP #XRPL
The vulnerability had been hidden in the XRP Ledger’s payment engine since 2015. By exploiting an arithmetic overflow, an attacker could theoretically create new coins out of thin air with only a few hundred XRP in upfront costs.
Fortunately, after investigating, the developers said they found no evidence that the vulnerability had been exploited on the public network.
But what happened next is the really interesting part.
Normally,
major protocol changes to the XRPL have to go through the amendment process: validators must reach over 80% consensus, and that consensus must be maintained for two weeks before the change takes effect.
But this time, the developers took a different approach. They upgraded the node software to version 3.4.1, which enabled the fix.
According to the official report, this was the first time in the more than ten years since the amendment process was introduced that this kind of emergency fix had been used.
The reason is easy enough to understand.
Once a vulnerability is made public, hackers may start looking for ways to exploit it. Having to wait two weeks for a vote would leave the network exposed to risk during that time.
So the fix was given the highest priority. On the day it was released, over 80% of the nodes on the default validator list had already upgraded—even though the source code for the fix had not yet been made public.
That’s the most important thing to discuss about this whole incident.
People often emphasize blockchain decentralization, transparency, and on-chain governance. But when a serious vulnerability could threaten the entire network’s supply, a trade-off has to be made between security and the usual governance process.
Regular XRP holders don’t need to change wallets because of this vulnerability. Those running nodes should make sure their software has been upgraded.
The crypto world talks endlessly about how important decentralization is. But if a vulnerability could let someone mint coins out of thin air, would you rather wait two weeks for the process to run its course, or support plugging the hole first?
$XRP #XRPL