XRP Ledger Patches 2015 Bug That Could Create XRP From Nothing
Security

XRP Ledger Patches 2015 Bug That Could Create XRP From Nothing

October 11, 20263 min read

XRP Ledger developers have closed a vulnerability that since 2015 could in theory have been used to create new XRP out of thin air. A counting error in the native exchange could have broken the network's main promise that the total supply of 100 billion coins never changes. Here is how the bug worked and why the network's own checks missed it.

What exactly did the researchers find?

The flaw was found by researcher Cayden Liao together with the Veria AI system, and it was reported to the developers on Sept. 22. Engineers at RippleX, Ripple's developer arm, reproduced the attack on a standalone server and confirmed that the newly created coins could be spent in a later transaction. An emergency software release with the fix followed.

In short: a counting error in the XRP Ledger exchange let an attacker buy up offers while paying almost nothing, and the sellers still got paid in full.

According to CoinDesk, the defect dates to 2015, so it sat in the code for almost ten years. It joins a run of long-hidden flaws that have been surfaced with AI help since July. Among them are the Coldcard wallet bug behind the theft of at least 1,367 Bitcoin and the problems that forced Core Lightning node operators to disconnect.

Some context. XRP is not mined and is not issued on a schedule. All the coins existed from the start, and there is no inflation by design. So any route to new coins, even a theoretical one, hits not fees or speed but a basic property of the asset.

How did the trick work?

The XRP Ledger has a native exchange where participants post offers to swap a token for XRP. The vulnerability hid in how the software adds up the amounts from many such offers within one payment. This is what the theoretical attack looked like.

  • Setup: the attacker opens a few hundred accounts, which takes only a few hundred XRP, most of which can be recovered.
  • Each account posts an offer with a tiny amount of a token in exchange for an unusually large amount of XRP.
  • A single payment buys every offer at once.
  • The total owed is too large for the software to count correctly, and the buyer is charged almost nothing.

The sellers still get paid in full. The upshot is that the attacker ends up with coins that did not exist before, and they can be spent like any other.

One important detail is that the attack needed neither stolen keys nor access to anyone else's wallet. Everything ran through ordinary actions open to anybody, namely opening accounts, posting offers and sending a payment. That is what separates logic errors from classic hacks.

Key parameters
Maximum XRP supply100 billion
Age of the bugsince 2015
Reported to developersSept. 22
Cost of the attacka few hundred XRP plus fees

Why did the network's own checks not stop it?

After every transaction the network checks that no new XRP has appeared. But that check relied on the same miscounted total, so the mismatch went unnoticed. A separate limit on how much XRP a single account can receive would not have triggered either, because the attack spread the coins across hundreds of accounts.

Put simply, both safeguards looked at one false number. Hence the small starting capital the researchers needed for their demonstration.

Developers know this situation well. When a control takes the same data as the main logic, an error in the data breaks both layers at once. An independent check that counts coins by another route catches such mismatches, and it is usually what people talk about after incidents like this.

Why was it serious for the market?

All 100 billion XRP were created when the ledger launched in 2012, and the software is built so that no new coins can be added. Institutions that use the network rely on that cap. An attacker could have created coins and sold them on exchanges, which would have put trust in the fixed-supply rule itself at risk.

For XRP holders the consequences would have been direct, because new coins on the market press on the price and doubts about the cap knock out the token's value story as well.

What does it mean for a user?

The discovery was made not by an auditor in the usual mode but by a pair of a researcher and an AI system. Such tools read code faster and reach narrow corners that a manual review rarely visits. Attackers can do the same, so it now matters who finds the flaw first.

The hole was closed with an emergency release, and the details became public only after the fix. The run of discoveries since July does not seem to be over, because AI tools now find defects that people missed for years. Fast updates of network software have become as much a part of crypto hygiene as checking an address before a transfer.

Comments

Your email address will not be published. Required fields are marked *

or verify by email