#xrpledgerpatchesxrpcreationbug
XRP's Fixed Supply Just Survived a Bug That Sat in the Code for About a Decade
"Fixed supply" is one of the strongest claims in crypto. This week, XRP Ledger disclosed a flaw that could have tested it.
Here's the timeline: researcher Cayden Liao reported the issue through the XRPL bug bounty program on September 22. It was a payment-engine integer overflow: when one payment consumed many DEX offers, unchecked 64-bit arithmetic could wrap the total to a smaller number while sellers still received the full amounts, with the difference becoming newly created, spendable XRP. The flaw may date to 2015. RippleX reproduced the attack and shipped a fix in xrpld 3.4.1 on September 25, then disclosed everything on October 9. It reportedly required hundreds of crafted offers and a few hundred XRP in reserves and fees, and the team found no evidence of exploitation, loss of funds, or key exposure. A separate, lower-severity batch-transaction issue was fixed through an amendment that went live the same day.
Why does this matter? The patch skipped the usual amendment vote, which normally requires over 80% validator support for two weeks, since public voting would have advertised the weakness. That's a reasonable security call, but it shows how much trust rests with core developers and with operators upgrading quickly. It also shows a bug bounty doing its job.
When secrecy and open governance pull in opposite directions during a critical fix, which should win? 🤔
#xrp #XRPL #CryptoSecurity #BugBounty
$XRP $MAGIC $LUMIA
XRP's Fixed Supply Just Survived a Bug That Sat in the Code for About a Decade
"Fixed supply" is one of the strongest claims in crypto. This week, XRP Ledger disclosed a flaw that could have tested it.
Here's the timeline: researcher Cayden Liao reported the issue through the XRPL bug bounty program on September 22. It was a payment-engine integer overflow: when one payment consumed many DEX offers, unchecked 64-bit arithmetic could wrap the total to a smaller number while sellers still received the full amounts, with the difference becoming newly created, spendable XRP. The flaw may date to 2015. RippleX reproduced the attack and shipped a fix in xrpld 3.4.1 on September 25, then disclosed everything on October 9. It reportedly required hundreds of crafted offers and a few hundred XRP in reserves and fees, and the team found no evidence of exploitation, loss of funds, or key exposure. A separate, lower-severity batch-transaction issue was fixed through an amendment that went live the same day.
Why does this matter? The patch skipped the usual amendment vote, which normally requires over 80% validator support for two weeks, since public voting would have advertised the weakness. That's a reasonable security call, but it shows how much trust rests with core developers and with operators upgrading quickly. It also shows a bug bounty doing its job.
When secrecy and open governance pull in opposite directions during a critical fix, which should win? 🤔
#xrp #XRPL #CryptoSecurity #BugBounty
$XRP $MAGIC $LUMIA
