100 Billion Xrp Supply Was Nearly Broken By A 10-Year Bug
- A flaw in the XRP Ledger’s payment software could have let an attacker create spendable XRP out of thin air, according to a security report published Friday.
- XRP’s supply is capped at 100 billion tokens, and the token is worth about $88.8 billion at $1.41.
- RippleX, Ripple’s developer arm, said it found no sign anyone used the flaw.
- The XRP Ledger has a built-in marketplace where accounts list offers to trade one token for another.
What Happened
This fix, released in server software version 3.4.1 on September 25, took effect as soon as each operator upgraded.
“This is the first time a change to transaction processing has deliberately shipped this way since the amendment system was introduced more than ten years ago,” RippleX indicated.
RippleX said a public vote would have exposed the bug in open code for weeks while it stayed exploitable. More than 80% of default validators upgraded on release day, before the fix’s code was published.
Market Context
XRP’s supply is capped at 100 billion tokens, and the token is worth about $88.8 billion at $1.41. RippleX, Ripple’s developer arm, said it found no sign anyone used the flaw.
The XRP Ledger has a built-in marketplace where accounts list offers to trade one token for another.
The disclosure lands a day after Cyber Capital founder Justin Bons called selling XRP as decentralized “fraud,” in an XRP decentralization debate with Ripple’s David Schwartz. The report says the XRPL Foundation, RippleX, and validators made the call together.
Why It Matters
A flaw in the XRP Ledger’s payment software could have let an attacker create spendable XRP out of thin air, according to a security report published Friday. The bug had likely gone unnoticed since 2015.
How One Payment Could Have Printed New XRP
According to the report, an attacker could open a few hundred accounts. Each would offer a tiny amount of a token in exchange for a huge amount of XRP.
Details
A single payment would then buy every offer at once. The software’s running total grew too large for its counter and reset to a tiny number, much like an odometer rolling past its limit.
The selling accounts were paid in full while the buyer paid almost nothing. A safety check meant to spot new XRP used the same counter, so it missed the gap too.
Researcher Cayden Liao and Veria AI reported the flaw through the XRPL bug bounty program on September 22.
Why Ripple Bypassed the XRP Ledger Validator Vote
Rule changes on the XRP Ledger normally need backing from more than 80% of trusted validators, the servers that confirm transactions, for two weeks.
RippleX said votes remain the rule for future changes.
The post 100 Billion XRP Supply Was Nearly Broken by a 10-Year Bug appeared first on BeInCrypto.