[XRP Ledger patches a decade-old payment engine overflow vulnerability that could theoretically mint trillions of XRP] According to The Block, the XRP Ledger has patched a critical integer overflow vulnerability in its payment engine that has existed since 2015. The flaw could theoretically allow a single transaction to mint XRP far exceeding the 100 billion supply cap, with the newly minted tokens fully transferable. The vulnerability was discovered by an AI agent from security firm Veria Labs, with co-founder Cayden Liao submitting the report; the team received the maximum $250,000 bounty under the program. RippleX released an emergency fix in version xrpld 3.4.1 on September 25, bypassing the standard validator voting process so the upgrade takes effect immediately. No evidence of exploitation on public networks has been detected. The vulnerability stems from the payment engine lacking overflow checks when aggregating order amounts. An attacker could set up hundreds of limit order accounts and craft malicious orders, enabling an attack with a single payment transaction. Sellers would receive the full amount of XRP, while the attacker pays only minimal fees; the network’s native anti-inflation checks fail to block the attack due to the same arithmetic overflow. This attack cannot be triggered accidentally—it requires specially constructed orders and dedicated transactions to activate.
XRP Ledger Patches 10-Year-Old Overflow Vulnerability That Could Mint Trillions of XRP
Share
The XRP Ledger patched a high-severity vulnerability in its payment engine—a flaw dating back to 2015. The integer overflow issue could have permitted the minting of trillions of XRP, exceeding the 100 billion supply cap. A security breach was detected by an AI agent from Veria Labs, with co-founder Cayden Liao receiving a $250,000 bounty. RippleX released an emergency fix in xrpld 3.4.1 on September 25, bypassing the validator voting process. The vulnerability arose from a missing overflow check during order aggregation, enabling abnormal transactions. No exploitation has been detected on the public network.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.