XRP Ledger patches 2015-era bug that could have created new XRP from nothing
In brief
- Researcher Cayden Liao and Veria AI found the payment flaw, believed to date to 2015.
- The attack abused the ledger's built-in exchange using hundreds of accounts and one payment.
- RippleX reproduced the attack and confirmed the created XRP could be spent later.
- xrpld 3.4.1 shipped the fix on Sept. 25 without disclosing what it repaired.
- RippleX said it found no evidence the flaw was exploited on any public network.
How the attack worked
The exploit ran through the ledger's built-in exchange, where accounts post offers to swap one token for another. According to the security report, an attacker would open hundreds of accounts, have each one offer a tiny amount of a token for an unusually large amount of XRP, then send a single payment that bought every offer at once.
That's where the math broke.
The total XRP owed would've been too large for the software to count correctly, so the selling accounts got paid in full while the buying account was charged almost nothing. The ledger does run a check after every transaction to make sure no new XRP has appeared (but that check relied on the same miscounted total, so it would've missed the creation). A separate limit on how much XRP a single account can receive wouldn't have triggered either. The attack spread the XRP across hundreds of accounts.
It wasn't costly to set up. The researchers' method needed only a few hundred XRP to open the accounts, most of which could be recovered, plus transaction fees.
A fixed supply, and a quiet fix
All 100 billion XRP were created when the ledger launched in 2012, and its software was built so no more could be added. This flaw cut straight against that rule. CoinDesk reported that an attacker could have created XRP from nothing and sold it on exchanges, undercutting a supply cap that institutions using the network rely on.
Engineers at RippleX, Ripple's developer arm, reproduced the attack on a standalone server and confirmed the newly created XRP could be spent in a later transaction. The bug was internally reported on Sept. 22, and developers shipped the fix in xrpld 3.4.1, the ledger's server software, on Sept. 25 without disclosing what it repaired.
Part of a wider pattern
The XRP Ledger isn't alone here. CoinDesk places the incident in a run of long-hidden crypto security flaws surfaced with AI help since July, including a Coldcard wallet bug behind the theft of at least 1,367 BTC and vulnerabilities that led Core Lightning to tell bitcoin node operators to disconnect.
Frequently asked questions
How could the XRP Ledger bug create XRP from nothing?
According to the security report, an attacker would open hundreds of accounts offering tiny token amounts for unusually large amounts of XRP, then buy every offer in one payment. The total XRP owed was too large for the software to count correctly, so sellers were paid in full while the buyer was charged almost nothing.
Why didn't the XRP Ledger's safety checks catch the attack?
The ledger's post-transaction check for new XRP relied on the same miscounted total, so it would have missed the creation. A separate per-account receive limit wouldn't have triggered because the attack spread the XRP across hundreds of accounts.
Was the XRP Ledger flaw ever exploited?
RippleX said it found no evidence the flaw was exploited on any public network. Its engineers reproduced the attack on a standalone server, and developers shipped a fix in xrpld 3.4.1 on Sept. 25 without disclosing what it repaired.


