BTC $82,699.00 +0.37%
ETH $2,493.92 -0.03%
BNB $748.66 +0.83%
XRP $1.41 +0.62%
SOL $109.80 -0.59%
TRX $0.3306 -0.41%
DOGE $0.0862 +1.05%
ADA $0.2535 +5.97%
BCH $278.45 -0.93%
LINK $12.90 +0.05%
HYPE $84.16 -1.63%
AAVE $174.75 +2.85%
SUI $1.10 +3.15%
XLM $0.1967 +0.85%
ZEC $1,225.54 +0.44%
AAPL $336.64 -0.44%
AMZN $262.68 +2.60%
GOOGL $352.93 +0.91%
MSFT $535.47 +2.20%
META $720.14 -0.25%
NVDA $230.48 -1.24%
TSLA $383.33 +1.34%
SNDK $1,589.67 -3.39%
INTC $104.74 -4.07%
SPCX $163.16 -1.71%
MU $1,032.78 -2.43%
AMD $609.96 -3.17%
BTC $82,699.00 +0.37%
ETH $2,493.92 -0.03%
BNB $748.66 +0.83%
XRP $1.41 +0.62%
SOL $109.80 -0.59%
TRX $0.3306 -0.41%
DOGE $0.0862 +1.05%
ADA $0.2535 +5.97%
BCH $278.45 -0.93%
LINK $12.90 +0.05%
HYPE $84.16 -1.63%
AAVE $174.75 +2.85%
SUI $1.10 +3.15%
XLM $0.1967 +0.85%
ZEC $1,225.54 +0.44%
AAPL $336.64 -0.44%
AMZN $262.68 +2.60%
GOOGL $352.93 +0.91%
MSFT $535.47 +2.20%
META $720.14 -0.25%
NVDA $230.48 -1.24%
TSLA $383.33 +1.34%
SNDK $1,589.67 -3.39%
INTC $104.74 -4.07%
SPCX $163.16 -1.71%
MU $1,032.78 -2.43%
AMD $609.96 -3.17%

XRP Ledger fixes a significant vulnerability that existed for nearly 11 years: attackers could have exploited it to generate XRP out of thin air

2026-10-10 12:24:02

The XRP Ledger recently fixed a payment system vulnerability that could be traced back to 2015. This vulnerability could allow attackers to bypass the system's calculation limits on token exchange amounts through a specially designed payment transaction, generating and spending large amounts of XRP out of thin air, undermining the mechanism that caps the total supply of XRP at 10 billion.

It was disclosed that attackers could create hundreds of accounts, allowing these accounts to post offers to exchange a small amount of tokens for a large amount of XRP, and then execute a transaction simultaneously. Due to a flaw in the software's calculation of the total transaction amount, the seller's account could receive the full XRP, while the buyer's account would need to pay almost nothing. Researchers Cayden Liao and Veria AI reported the vulnerability on September 22, and RippleX subsequently reproduced the attack and confirmed that the generated XRP could be used in subsequent transactions. RippleX stated that there is currently no evidence that this vulnerability has been exploited on any public network. The development team released version 3.4.1 of xrpld on September 25 to fix the vulnerability.

app_icon
ChainCatcher Building the Web3 world with innovations.