XRP Ledger Patches Decade-Old Bug That Could Have Broken Its 100 Billion Supply Cap

iconBlockchainreporter
Share
AI summary iconSummary
XRP Ledger developers disclosed on-chain news on Oct. 9 about a critical integer overflow bug in the payment engine that could have allowed attackers to mint new XRP tokens, breaking the 100 billion supply cap. The flaw, present since 2015, was patched in the xrpld 3.4.1 release on Sept. 25. Cayden Liao and Veria AI reported the vulnerability, which RippleX classified as critical and fixed without the usual amendment process. The same network upgrade also resolved a Batch transaction wrapper validation flaw activated on mainnet on Oct. 9.
Ripple Main2

XRP Ledger developers disclosed on Oct. 9 that an integer overflow bug in the network’s payment engine could have let an attacker create new XRP out of nothing, breaking the 100 billion token supply cap set when the ledger launched in 2012. The flaw was patched in the xrpld 3.4.1 software release on Sept. 25, and RippleX said it found no evidence the bug was ever exploited on a public network, according to the official vulnerability disclosure report.

The bug was reported through the XRPL bug bounty program by researcher Cayden Liao and Veria AI on Sept. 22. RippleX engineers reproduced the attack on a standalone server, confirmed the newly created XRP could be spent in a follow-up transaction, and raised the finding’s severity from major to critical.

How the Bug Could Have Minted XRP

The vulnerability sat in the payment engine’s overflow handling. When a single payment consumed many offers on the ledger’s built-in exchange, the software summed what the buyer owed using 64-bit integer addition with no overflow check. A few hundred offers, each asking for a very large amount of XRP, could push that total past what a 64-bit number can hold, wrapping it around to a tiny value. Each offer owner was then paid in full while the buyer was charged only the wrapped total, leaving newly minted XRP in the attacker’s accounts.

Two safety checks should have caught this and did not. The ledger’s “no XRP created” invariant sums net balance changes the same way, so it wrapped around identically and saw nothing wrong. A per-account balance check only fails when a single account holds more than the total supply, which the attack avoided by spreading the minted XRP across hundreds of accounts.

Why the Fix Skipped the Amendment Process

Changes to how the XRP Ledger processes transactions normally ship through an amendment process, in which a new rule stays dormant until more than 80 percent of trusted validators support it for two weeks. RippleX deliberately skipped that process for the first time since it was introduced more than ten years ago, because the exploit was cheap, required no special access, and could have minted spendable XRP. Since xrpld is open source, a fix published through the normal route would have sat visible but still exploitable on mainnet for weeks.

The shortcut carried its own risk of a mixed-version network halt, but normal transactions never reach the vulnerable code path. More than 80 percent of default UNL validators were running 3.4.1 on the day it was released, before the source code was published.

What It Means for XRP’s Fixed Supply

The episode underscores how much of XRP’s value proposition depends on its supply being provably finite. All 100 billion tokens were created at launch, and institutions building on the ledger treat that cap as a guarantee. The bug had been present since the current payment engine was written in 2015, yet RippleX found no evidence it was ever exploited.

The same release also fixed a separate Batch transaction wrapper validation flaw, which was activated on mainnet on Oct. 9. RippleX said it is adding a re-verification step to its release process so every security finding marked as fixed is re-tested against the release candidate. The disclosure arrives as the XRP Ledger continues to add institutional features, including permission delegation for banks and stablecoins, while XRP’s supply and escrow dynamics remain in focus for holders.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.