Security· ★★★★· neutral·

XRP Ledger patched decade-old bug that could mint XRP from nothing

  • —The bug in the ledger's built-in exchange let hundreds of accounts receive large XRP amounts while the buyer paid almost nothing
  • —The miscounted total bypassed both the post-transaction supply check and the per-account receive limit
  • —The attack needed only a few hundred XRP to open accounts, most of it recoverable, plus transaction fees
  • —RippleX shipped the fix in xrpld 3.4.1 on Sept. 25 without disclosing what it repaired
Why it matters: The flaw threatened XRP's fixed supply cap, which institutional users of the network rely on.
Source: CoinDesk