XRP Ledger patched decade-old bug that could create billions of dollars in XRP from nothing
Researchers demonstrated how a payment could create spendable XRP without the sender funding it, prompting an emergency software release.
A flaw in the XRP Ledger’s payment system could have let an attacker create large amounts of new XRP without paying for it, breaking the token’s fixed-supply rule, according to a security report published Friday.
The bug, believed to date to 2015, was found by researcher Cayden Liao and Veria AI and internally reported on Sept. 22. Engineers at RippleX, Ripple’s developer arm, reproduced the attack on a standalone server and confirmed the newly created XRP could be spent in a later transaction.
All 100 billion XRP were created when the ledger launched in 2012, and its software is built so no more can ever be added. But the security vulnerability could have allowed an attacker to create XRP from nothing and sell it on exchanges, undercutting a supply cap that institutions using the network rely on.
The attack worked through the ledger’s built-in exchange, where accounts post offers to swap one token for another.
An attacker would open hundreds of accounts, have each one offer a tiny amount of a token in exchange for an unusually large amount of XRP, then send a single payment that bought every offer at once.
The total XRP owed would be too large for the software to count correctly, so the attacker’s selling accounts would be paid in full while the buying account was charged almost nothing — leaving the attacker with XRP that hadn’t existed before.
The XRP Ledger runs a check after every transaction to make sure no new XRP has appeared, but that check relied on the same miscounted total and would have missed it. A separate limit on how much XRP a single account can receive wouldn’t have triggered either, because the attack spread the XRP across hundreds of accounts.
The researchers’ method needed only a few hundred XRP to open those accounts, most of which could be recovered, plus transaction fees.
Developers shipped the fix in xrpld 3.4.1, the ledger’s server software, on Sept. 25 without disclosing what it repaired.
The incident joins a run of long-hidden crypto security flaws surfaced with AI help since July, including the Coldcard wallet bug behind the theft of at least 1,367 BTC and the vulnerabilities that forced Core Lightning to tell bitcoin node operators to disconnect.
Diversified RWA stablecoins sustain 5-7% yield from real credit as crypto funding compresses to ~4%. GENIUS pushes yield off-chain; TAM grows to $4B in 3 years.
Asanat Analysis — Why it matters
A decade-old vulnerability in XRP Ledger's payment logic allowed attackers to mint XRP without corresponding value destruction—a critical flaw that undermines the ledger's scarcity model. The bug's longevity despite XRPL's maturity raises questions about code review practices in production blockchain systems and suggests similar vulnerabilities could persist in other legacy chains. The emergency patch indicates the issue was responsibly disclosed, but the gap between discovery and fix reveals real risks in decentralized systems where coordination delays can be costly.
This incident signals broader infrastructure fragility: XRP Ledger processes billions in value daily, yet a payment-layer bug nearly compromised its monetary base integrity. The patch's necessity demonstrates that 'open' auditing doesn't guarantee security—many eyes can miss decades-old issues if they're sufficiently subtle. For XRPL's use case in institutional settlement, the episode undercuts confidence messaging around blockchain stability, though rapid remediation partially mitigates reputational damage. The story also highlights why major DeFi protocols now employ continuous formal verification rather than relying solely on penetration testing.