XRP Ledger Has 11-Year-Old Bug That Could Have Let Attackers Mint XRP

Market Intel · Just now · Not financial advice

A security researcher has disclosed an eleven-year-old bug in the XRP Ledger that could have allowed an attacker to mint XRP out of existence. The vulnerability was present in the ledger's consensus protocol but was patched before it could be exploited.

The bug involved a flaw in the way the ledger handled a specific type of transaction under certain network conditions. In theory, an attacker who understood the flaw could have created a transaction that the consensus protocol accepted as valid but that minted XRP without a corresponding debit.

The XRP Ledger's development team patched the vulnerability in a recent software update and stated that no XRP was minted through the exploit. The patch was applied through the normal validator upgrade process.

The disclosure highlights the challenge of maintaining security in a codebase that has been in continuous operation for over a decade. The XRP Ledger launched in 2012, making it one of the oldest blockchain networks still in operation.

The bug was discovered through a routine security audit rather than through an active exploit. The researcher responsible for the discovery has published a technical write-up describing the vulnerability in detail.

↑ Back to top