FinanceFeedsCrypto

XRP Ledger Fixed a Bug From 2015 That Could Have Created…

By Abdelaziz Fathi

Photo for: XRP Ledger Fixed a Bug From 2015 That Could Have Created…

AI summary of the source article

The XRP Ledger patched a critical 2015 vulnerability that could have allowed an attacker to create spendable XRP via an integer overflow. The flaw was reported on September 22 and patched on September 25 in version 3.4.1.

Why it matters

The flaw could have allowed an attacker to bypass "one of the network's most basic monetary rules: no more than the original 100 billion XRP are supposed to exist."

Key facts

  • The 64-bit integer overflow flaw in the payment engine existed since 2015 and could have allowed the creation of unfunded, spendable XRP.
  • Reported by Cayden Liao and Veria AI on September 22, the issue was patched in xrpld 3.4.1 on September 25 and publicly disclosed on October 9.
  • Developers found no evidence that the issue was exploited on any public network.

Source excerpt · FinanceFeeds

The XRP Ledger fixed a decade-old software flaw that could have allowed an attacker to create spendable XRP without funding it, bypassing one of the network's most basic monetary rules: no more than the original 100 billion XRP are supposed to exist. The vulnerability was reported on September 22 by researcher Cayden Liao and Veria AI through the XRPL bug bounty program. RippleX engineers reproduc…