mt logoMyToken
ETH Gas
Tiếng việt

XRP Ledger Patches Decade-Old Bug That Could Have Broken Its 100 Billion Supply Cap

sưu tầmcollect
đăng lạishare
Ripple Main2

XRP Ledger developers disclosed on Oct. 9 that an integer overflow bug in the network’s payment engine could have let an attacker create new XRP out of nothing, breaking the 100 billion token supply cap set when the ledger launched in 2012. The flaw was patched in the xrpld 3.4.1 software release on Sept. 25, and RippleX said it found no evidence the bug was ever exploited on a public network, according to the official vulnerability disclosure report .

The bug was reported through the XRPL bug bounty program by researcher Cayden Liao and Veria AI on Sept. 22. RippleX engineers reproduced the attack on a standalone server, confirmed the newly created XRP could be spent in a follow-up transaction, and raised the finding’s severity from major to critical.

How the Bug Could Have Minted XRP

The vulnerability sat in the payment engine’s overflow handling. When a single payment consumed many offers on the ledger’s built-in exchange, the software summed what the buyer owed using 64-bit integer addition with no overflow check. A few hundred offers, each asking for a very large amount of XRP, could push that total past what a 64-bit number can hold, wrapping it around to a tiny value. Each offer owner was then paid in full while the buyer was charged only the wrapped total, leaving newly minted XRP in the attacker’s accounts.

Two safety checks should have caught this and did not. The ledger’s “no XRP created” invariant sums net balance changes the same way, so it wrapped around identically and saw nothing wrong. A per-account balance check only fails when a single account holds more than the total supply, which the attack avoided by spreading the minted XRP across hundreds of accounts.

Why the Fix Skipped the Amendment Process

Changes to how the XRP Ledger processes transactions normally ship through an amendment process, in which a new rule stays dormant until more than 80 percent of trusted validators support it for two weeks. RippleX deliberately skipped that process for the first time since it was introduced more than ten years ago, because the exploit was cheap, required no special access, and could have minted spendable XRP. Since xrpld is open source, a fix published through the normal route would have sat visible but still exploitable on mainnet for weeks.

The shortcut carried its own risk of a mixed-version network halt, but normal transactions never reach the vulnerable code path. More than 80 percent of default UNL validators were running 3.4.1 on the day it was released, before the source code was published.

What It Means for XRP’s Fixed Supply

The episode underscores how much of XRP’s value proposition depends on its supply being provably finite. All 100 billion tokens were created at launch, and institutions building on the ledger treat that cap as a guarantee. The bug had been present since the current payment engine was written in 2015, yet RippleX found no evidence it was ever exploited.

The same release also fixed a separate Batch transaction wrapper validation flaw, which was activated on mainnet on Oct. 9. RippleX said it is adding a re-verification step to its release process so every security finding marked as fixed is re-tested against the release candidate. The disclosure arrives as the XRP Ledger continues to add institutional features, including permission delegation for banks and stablecoins , while XRP’s supply and escrow dynamics remain in focus for holders.

Tuyên bố từ chối trách nhiệm: Bản quyền của bài viết này thuộc về tác giả gốc và không đại diện cho MyToken(www.mytokencap.com)Ý kiến ​​và vị trí; vui lòng liên hệ với chúng tôi nếu bạn có thắc mắc về nội dung
community_x_prefix
X(https://x.com/MyTokencap)
community_tg_prefixcommunity_tg_name
(https://t.me/mytokenGroup)
Đọc liên quan