A critical flaw in XRP Ledger that could have allowed new XRP to be created and spent beyond the fixed supply has been patched. The Defiant reported on Friday that RippleX and the XRP Ledger Foundation disclosed a payment engine vulnerability that had remained in the code since 2015.
The flaw was reported on Sept. 22 through the XRPL bug bounty programme, and the fix was included in xrpld 3.4.1 released on Sept. 25. More than 80 percent of UNL, the default trusted validator list, was already running that or a higher version at the time of disclosure on Oct. 9.
RippleX engineers reproduced the vulnerability on a local standalone server and confirmed that newly created XRP could be used in subsequent payments. No signs were found that the vulnerability was exploited on the public network.
Researcher Aiden Liao (랴오) said in a technical document written with Veria AI that a single successful exploit could have created about 18,450,000,000,000,000 XRP. That compares with an initial XRP supply of 100,000,000,000. Liao also said his team received the bug bounty programme’s maximum reward of $250,000.