uMaHF0G5M1jYL9t88qHEEkQggU6GJ5wTZlhvItt7
Bookmark

XRPL Fixes Decade-Old Bug That Could Have Created 18 Trillion XRP

XRP Ledger security update addressing a decade-old payment-engine vulnerability that could have enabled the creation of 18 trillion XRP.

XRP Ledger security update addressing a decade-old payment-engine vulnerability that could have enabled the creation of 18 trillion XRP.

The XRP Ledger (XRPL) has fixed a critical software vulnerability that could have allowed an attacker to create approximately 18 trillion XRP in a single transaction, potentially bypassing the network's fixed supply of 100 billion tokens. The flaw, which originated in code dating back to 2015, was disclosed by RippleX and the XRP Ledger Foundation after being reported through the network's bug bounty program.

The vulnerability was patched in xrpld 3.4.1 on September 25. According to Wu Blockchain the disclosure, more than 80% of default validators had upgraded to the fixed version that day. XRPL also reported that it found no evidence the vulnerability had ever been exploited on a public network.

Vulnerability Could Have Bypassed XRP's Supply Limit

The security issue involved an overflow bug in the XRP Ledger's payment engine. Under specific conditions, a specially crafted transaction could have exploited the flaw to create spendable XRP beyond the supply intended by the protocol.

XRP has a fixed intended supply of 100 billion tokens. A vulnerability capable of bypassing that limit would have represented a significant threat to the ledger's monetary rules, as the creation of additional spendable tokens could undermine the integrity of its supply accounting.

Security researcher Cayden Liao, whose team developed a proof of concept demonstrating the issue, said the exploit could have generated approximately 18 trillion XRP through a single transaction. That amount would have been roughly 184 times the network's intended 100 billion XRP supply.

The reported figure illustrates the potential scale of the vulnerability. Rather than being limited to a relatively small accounting discrepancy, the flaw could have enabled the creation of an amount of XRP vastly exceeding the supply established by the network's design.

Researcher Receives Maximum $250,000 Bounty

The vulnerability was reported through the XRPL bug bounty program, which provides a channel for security researchers to disclose flaws in the ledger's software. Liao's team received the program's maximum bounty of $250,000 for identifying and demonstrating the issue.

The award reflects the severity assigned to the reported vulnerability and the potential consequences of a successful exploit. The proof of concept provided a demonstration of how a specially constructed transaction could have triggered the payment-engine markets overflow, rather than merely identifying a theoretical weakness in the code.

The discovery also highlights the role of external security researchers in identifying vulnerabilities in established blockchain infrastructure. In this case, the affected code dated back to 2015, meaning the flaw had existed in the software for years before its disclosure and subsequent correction.

XRPL Releases Patch and Reports No Known Exploitation

XRPL addressed the vulnerability through the release of xrpld 3.4.1 on September 25. More than 80% of default validators had upgraded that day, according to the reported disclosure. Validators are an important part of the ledger's transaction-validation process, making software updates relevant to the network's overall security.

Despite the potential severity of the bug, XRPL said it found no evidence that the vulnerability had been exploited on a public network. The disclosure therefore distinguishes between the demonstrated ability to exploit the flaw under controlled conditions and evidence of an actual attack against the live network.

The issue's resolution addresses a vulnerability finance that could have threatened the XRP Ledger's fixed-supply design. The reported proof of concept demonstrated the potential to create approximately 18 trillion XRP in one transaction, while the September 25 patch and validator upgrades marked the immediate response to the security finding.

Writer: Victoria Hale  
Technology & Blockchain Writer

Victoria Hale writes about blockchain technology, digital infrastructure, and the intersection of emerging technologies with finance. Her articles explore how new protocols and systems are shaping the evolving digital economy.

She prioritises clarity and accuracy when explaining technical developments to a general audience.

Check out other news and articles on Google News

Disclaimer:

The articles on Hokanews are here to keep you updated on the latest buzz in crypto, tech, and beyond—but they’re not financial advice. We’re sharing info, trends, and insights, not telling you to buy, sell, or invest. Always do your own homework before making any money moves.

Hokanews isn’t responsible for any losses, gains, or chaos that might happen if you act on what you read here. Investment decisions should come from your own research—and, ideally, guidance from a qualified financial advisor. Remember:  crypto and tech move fast, info changes in a blink, and while we aim for accuracy, we can’t promise it’s 100% complete or up-to-date.

Stay curious, stay safe, and enjoy the ride! hoka.news