Science & Tech · Cybersecurity · 5 hrs ago
XRP Ledger patches bug that could have created counterfeit coins
The XRP Ledger, a large network used for XRP cryptocurrency, patched a flaw in its payment system.
The bug could have let a carefully constructed transaction create spendable XRP beyond the network’s fixed supply.
It involved a calculation that could overflow when one payment processed many offers in the network’s built-in trading system.
The flaw may have been present since 2015, but the disclosure says there is no evidence it was exploited on a public network.
Researcher Cayden Liao reported it through the network’s bug bounty program, and RippleX tested the issue.
The fix was released in xrpld 3.4.1 and took effect as servers upgraded, without the usual validator vote.
The unusual shortcut was intended to avoid leaving the flaw open during a vote, though the disclosure says upgrades carried a risk of splitting the network.
The XRP Ledger patched a flaw that could have let an attacker create counterfeit XRP and spend it.
The bug involved an integer overflow in the network’s payment engine when a payment consumed many order-book offers.
Researcher Cayden Liao reported the bug on September 22 through the XRPL bug bounty program.
An emergency xrpld software release followed on September 25, and the fix shipped in xrpld 3.4.1.
The disclosure report said there was no evidence the flaw had been exploited on any public network.
The fix took effect without the validator vote normally used for XRP Ledger rule changes.
- Who
- Cayden Liao reported the bug; the XRP Ledger patched it.
- What
- An integer overflow could have let an attacker create spendable XRP beyond the total supply.
- When
- Liao reported it on September 22; an emergency release followed on September 25. The year is not stated.
- Where
- The XRP Ledger.
- Why
- To prevent exploitation of the flaw, which could have enabled counterfeit XRP to be created and spent.
This story does not have two clearly opposing sides.
An attacker could have created spendable XRP far beyond the total supply in a single validated transaction.
We have found no evidence that this issue was exploited on any public network.
This is the first time a change to transaction processing has deliberately shipped this way since the amendment system was introduced more than ten years ago.
The disclosure report said the bug likely dated back to when the current payment engine was written.
Researcher Cayden Liao reported the bug through the XRPL bug bounty program.
An emergency release of the xrpld software followed.
The code was published on GitHub, according to the article.
- Researcher
- Cayden Liao
- Bug report
- September 22
- Emergency release
- September 25
- Patched software
- xrpld 3.4.1
- Potential impact
- Spendable XRP beyond the total supply











