BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Nearly 11-Year-Old Vulnerability Fixed: XRP Ledger Once Had a Payment System Flaw That Could Generate XRP Out of Thin Air

Odaily: XRP Ledger recently fixed a payment system vulnerability that may date back to 2015. The vulnerability could have allowed attackers to bypass the system's calculation limits on token exchange amounts through specially crafted payment transactions, generating and spending large amounts of XRP out of thin air, thereby undermining the mechanism capping XRP's total supply at 100 billion tokens. An attacker could create hundreds of accounts, have these accounts place offers to exchange small amounts of tokens for massive amounts of XRP, and then settle them all simultaneously through a single payment. Due to a flaw in the software's calculation of the total transaction amount, the seller accounts could receive the full amount of XRP while the buyer accounts would barely need to pay the corresponding amount. Researchers Cayden Liao and Veria AI reported the vulnerability on September 22, and RippleX subsequently reproduced the attack and confirmed that the generated XRP could be used in subsequent transactions. RippleX stated that there is currently no evidence that the vulnerability was ever exploited on any public network. The development team released xrpld version 3.4.1 on September 25 to fix the vulnerability.