ChainThink reports that the XRP Ledger has patched a payment system vulnerability that may have existed since 2015.
This vulnerability could allow an attacker to bypass the token exchange amount calculation limits through specially crafted payment transactions, generating and spending large amounts of XRP, thereby undermining the 100-billion-coin supply cap.
Attackers can create hundreds of accounts, place offers to exchange small amounts of tokens for large sums of XRP, and execute the trades simultaneously with a single payment. Due to a flaw in the system’s calculation of total transaction value, the seller’s account may receive all the XRP while the buyer pays almost nothing in return.
Researchers Cayden Liao and Veria AI reported the vulnerability on September 22, and RippleX subsequently reproduced the attack, confirming that the generated XRP could be used in subsequent transactions.
RippleX stated that there is currently no evidence the vulnerability has been exploited on any public network; the development team released version xrpld 3.4.1 to patch the vulnerability on September 25.

