Ripple Labs Releases Update to Address XRP Ledger Vulnerabilities
- Ripple Labs released xrpld 3.4.1 on September 25 to fix two vulnerabilities in the XRP Ledger server software.
- The first vulnerability, an integer overflow, could have allowed unbacked XRP creation and was discovered on September 22 through the XRPL bug bounty program.
- The second flaw involved batch transactions, potentially causing server versions to disagree, which could halt ledger validation under certain conditions.
- The XRPL team confirmed no evidence of exploitation of these vulnerabilities on public networks before the relevant protocol updates were activated.
- Version 3.4.1 added checks to prevent overflow errors and was part of ongoing security enhancements for XRPL.
These updates are critical for maintaining the integrity and security of the XRP Ledger as they address significant vulnerabilities that could disrupt network operations or allow unauthorized issuance of XRP.
The release of xrpld 3.4.1 demonstrates Ripple’s commitment to enhancing security, particularly given the potential risks associated with unbacked XRP creation and transaction inconsistencies.