XRP Ledger patched decade-old bug that could create billions of dollars in XRP from nothing
CoinDesk 2026-10-10 04:20:07
Context: The XRP Ledger, a cryptocurrency platform, had a decade-old bug that could have allowed attackers to create billions of dollars' worth of XRP from nothing, violating the token's fixed supply of 100 billion tokens. The bug, believed to have dated back to 2015, was discovered by researcher Cayden Liao and Veria AI, and was patched by RippleX on September 25. The vulnerability exploited a counting error in the XRP Ledger's built-in exchange.
Key Facts
- The XRP Ledger had a bug that could have allowed attackers to create and spend new XRP, violating the cryptocurrency's fixed supply of 100 billion tokens, and potentially creating billions of dollars in XRP from nothing.
- The bug, believed to have dated back to 2015, was discovered by researcher Cayden Liao and Veria AI, and internally reported on September 22.
- RippleX engineers reproduced the attack on a standalone server and confirmed that the newly created XRP could be spent in a later transaction, but found no evidence of exploitation on public networks.
- The bug was patched in the xrpld 3.4.1 software release on September 25, without disclosing what the fix repaired.