XRP Ledger Fixes Major Vulnerability Allowing Creation of XRP from Nothing
- An attacker could exploit the XRP Ledger by opening hundreds of accounts to manipulate token exchanges for large amounts of XRP.
- The attack involved sending a single payment that bought all offers at once, resulting in the creation of XRP that did not exist before.
- The bug was identified and patched in version xrpld 3.4.1 on September 25, without details on the specific fix being disclosed.
- This incident is part of a series of vulnerabilities uncovered since July, including flaws affecting Coldcard wallets and Core Lightning.
The vulnerability allowed for potential manipulation of the XRP supply through deceptive account activity, which could have led to significant financial implications if left unaddressed. Developers acted swiftly to implement a fix after identifying the risk.
With the patch now in place, the risk of artificially generating XRP has been mitigated following a critical update on September 25. (Source)