A security report published Friday by the XRP Ledger team discloses a vulnerability that, if exploited, could have allowed an attacker to create new XRP from nothing — breaking the ledger's foundational rule that no token can ever be minted beyond the 100 billion created at launch in 2012.
The disclosure report, covered by CoinDesk and 24/7 Wall St., says the flaw is believed to have existed since 2015 in the ledger's payment engine — specifically in how its built-in exchange tallies large multi-offer payments.
How the Attack Worked
The XRP Ledger's built-in exchange lets accounts post offers to swap one token for another. According to the report, an attacker could have opened hundreds of accounts, each offering a tiny amount of some token in exchange for an unusually large amount of XRP, then sent a single payment that purchased every offer at once.
The total XRP owed would be large enough to trip a counting error in the software. The attacker's selling accounts would be paid in full while the buying account was charged almost nothing — leaving the attacker holding XRP that had never existed, which engineers confirmed could be spent in a later transaction.
Two built-in safeguards failed to catch it. The ledger's post-transaction check for newly created XRP relied on the same miscounted total, and the per-account receive limit never triggered because the XRP was spread across hundreds of accounts. The setup cost was minimal: a few hundred XRP to open the accounts, most of it recoverable, plus transaction fees.
Discovery and Response
Researcher Cayden Liao and Veria AI reported the bug privately on September 22 through the XRP Ledger's bug bounty program, with a proof of concept that rated the finding as Major. Engineers at RippleX, Ripple's developer arm, reproduced the attack on a standalone server, and the fix shipped three days later in xrpld 3.4.1, the ledger's server software, on September 25 — without disclosing what it repaired. The public disclosure came roughly two weeks after the patch.
RippleX said it found no evidence the flaw was ever exploited on any public network. The report did not state whether any bounty payment was made.
Context
The disclosure joins a run of long-hidden crypto security flaws surfaced since July with AI-assisted research, including the Coldcard wallet bug behind the theft of at least 1,367 BTC and the vulnerabilities that forced Core Lightning to tell Bitcoin node operators to disconnect. For a ledger whose value proposition to institutions rests partly on its fixed supply, a decade-old counter flaw is a reminder that supply guarantees are only as strong as the oldest untested code path beneath them.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.