A severe flaw in the XRP Ledger's payment system allowed attackers to create new XRP without funding the tokens, a security report revealed Friday. This bug, believed to originate in 2015, directly threatened the network's fixed-supply rule, which guarantees only 100 billion XRP will ever exist.

Researcher Cayden Liao and Veria AI discovered the vulnerability, reporting it internally on Sept. 22. RippleX, Ripple's developer arm, confirmed the attack's viability by reproducing it on a standalone server. Tests showed the newly generated XRP was spendable in subsequent transactions.

RippleX reported no evidence of exploitation on any public network. The vulnerability presented a direct threat to the XRP Ledger's economic model, potentially allowing an attacker to generate XRP from nothing and sell it on exchanges.

The attack leveraged the ledger's built-in exchange mechanism. An attacker would open hundreds of accounts, each offering a small amount of a token in exchange for a disproportionately large amount of XRP. A single payment would buy all these offers simultaneously.

The software's internal accounting would miscount the total XRP owed due to the unusually large aggregate amount. This error caused the attacker's selling accounts to receive full payment while the buying account was charged almost nothing, effectively creating new XRP.

The XRP Ledger includes a post-transaction check to ensure no new XRP has appeared, but this check relied on the flawed total and failed to detect the inflation. A separate limit on how much XRP a single account could receive did not trigger, as the attack distributed the newly created XRP across hundreds of accounts.

Executing this exploit required minimal capital—only a few hundred XRP to establish the necessary accounts, most of which were recoverable, plus standard transaction fees.

Developers deployed a fix in xrpld 3.4.1, the ledger's server software, on Sept. 25. The update was released without public disclosure of the specific repair.

This incident adds to a series of long-hidden crypto security flaws brought to light with AI assistance since July. Past discoveries include a Coldcard wallet bug that led to the theft of at least 1,367 BTC and vulnerabilities that prompted Core Lightning to advise Bitcoin node operators to disconnect their systems.