Critical XRPL Bug Could Have Created Unlimited XRP
- The XRPL overflow bug was initially reported by Cayden Liao and Veria AI on Sept. 22, and RippleX rated it as critical.
- By Sept. 25, over 80% of default Unique Node List (UNL) validators had implemented the xrpld version 3.4.1 fix.
- The vulnerability involved unchecked arithmetic in the payment engine of XRP Ledger’s decentralized exchange (DEX), potentially allowing creation of non-existent XRP.
- No exploits were found upon public disclosure on Oct.9, coinciding with the activation of the fixBatchV1_2 amendment.
The XRPL overflow bug posed a significant threat to XRP‘s core promise due to its potential to create spendable XRP beyond the hard cap of tokens in a single transaction. The rapid response ensured that over four-fifths of validators applied the necessary patch within days, preventing any exploitation on public networks.
This incident highlights the importance of swift action in maintaining cryptocurrency integrity and stability, as evidenced by RippleX’s quick upgrade to address a critical flaw that could have undermined confidence in XRP’s fixed supply model.