The XRP Ledger has received a security patch for a bug that could have enabled an attacker to generate an enormous amount of XRP without any backing. According to a CoinDesk report, the vulnerability involved a technique where an attacker opens hundreds of accounts, each offering a tiny amount of a token in exchange for an unusually large amount of XRP. The attacker then sends a single payment that simultaneously buys every offer.
The total XRP owed would exceed the software's counting capacity, causing the ledger to miscalculate. As a result, the selling accounts would receive their full XRP payment while the buying account would be charged nearly nothing, effectively creating XRP from nothing. The ledger's post-transaction integrity check, designed to detect newly created XRP, would fail because it relied on the miscounted total. Additionally, per-account receiving limits would not trigger, as the attack distributed the XRP across hundreds of accounts.
The researchers' method required only a few hundred XRP to set up the accounts, making the attack feasible for a relatively low cost. The patch has been applied, and the ledger is now considered secure against this exploit. The discovery underscores ongoing security challenges in blockchain systems, where even long-standing protocols can harbor critical flaws.