header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

XRP Ledger Fixes Major Vulnerability That Went Unnoticed for Nearly 11 Years, Attackers Could Have Exploited It to Generate XRP Out of Thin Air

BlockBeats news, October 10: The XRP Ledger recently patched a payment system vulnerability that may date back to 2015. The vulnerability could have allowed attackers to bypass the system's calculation limits on token exchange amounts through a specially crafted payment transaction, generating and spending large amounts of XRP out of thin air, undermining the mechanism that caps the total XRP supply at 100 billion.


According to disclosures, attackers could create hundreds of accounts, have these accounts place offers to exchange small amounts of tokens for massive amounts of XRP, and then settle them all at once through a single payment. Due to a flaw in the software's calculation of the total transaction amount, the seller accounts could receive the full amount of XRP while the buyer accounts would barely need to pay the corresponding amount.


Researchers Cayden Liao and Veria AI reported the vulnerability on September 22, and RippleX subsequently reproduced the attack and confirmed that the generated XRP could be used in subsequent transactions. RippleX said there is currently no evidence that the vulnerability was ever exploited on any public network. The development team released xrpld version 3.4.1 on September 25 to fix the vulnerability.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish