XRPL Fixes Decade-Old Bug That Could Have Minted Trillions of XRP
RippleX and the XRP Ledger Foundation disclosed tha | Hanami
XRPL Fixes Decade-Old Bug That Could Have Minted Trillions of XRP
RippleX and the XRP Ledger Foundation disclosed that a critical payment-engine overflow bug could have allowed an attacker to create spendable XRP beyond the network’s fixed supply using a specially crafted transaction. The issue, present in code dating back to 2015, was reported through the XRPL bug bounty program and fixed in xrpld 3.4.1 on September 25, with more than 80% of default validators upgraded that day.
Security researcher @Cayden_Liao said his team’s proof of concept could mint about 18 trillion XRP in a single transaction, roughly 184 times XRP’s intended 100 billion supply, and earned the program’s maximum $250,000 bounty. XRPL said it found no evidence the flaw was ever exploited on a public network.