Researchers have identified a decade-old vulnerability in the XRP Ledger that could have enabled attackers to generate large quantities of spendable XRP without providing sufficient funds. The discovery prompted developers to release a software patch to address the security risk.
A security report published Friday detailed how the flaw could have allowed malicious users to create XRP without paying for it, potentially undermining the cryptocurrency’s fixed-supply limit. The vulnerability is believed to have been present since 2015.
Researcher Cayden Liao and Veria AI discovered the issue and privately reported it on Sept. 22. Engineers at RippleX, Ripple’s development division, replicated the exploit on an isolated server and confirmed that the newly generated XRP could be transferred or spent in subsequent transactions.
RippleX stated that it had found no evidence of the vulnerability being exploited on any public network.
The XRP Ledger launched in 2012 with a predetermined supply of 100 billion XRP, and its protocol is designed to prevent additional tokens from being created. The vulnerability, however, could have allowed attackers to produce XRP artificially and potentially sell it on exchanges, threatening the supply cap that institutions and other network participants depend on.
The exploit targeted the XRP Ledger’s native decentralized exchange, which allows users to place offers to exchange one token for another.
An attacker could theoretically have created hundreds of accounts, with each account offering a small amount of another token in exchange for an unusually large quantity of XRP. A single payment could then have triggered all those offers simultaneously.
The flaw involved an arithmetic error when calculating the total amount of XRP required to complete the transactions. As a result, the selling accounts could receive the full amount of XRP while the purchasing account was charged almost nothing. This discrepancy could have created new XRP without the corresponding funds ever being supplied.
The ledger’s post-transaction verification system is designed to detect any unauthorized increase in XRP supply. However, because the calculation itself could be incorrect, the security check might have failed to recognize the newly created tokens.
A separate safeguard limiting how much XRP an individual account could receive would also have been ineffective against this method. By distributing the tokens across hundreds of accounts, an attacker could have avoided exceeding the limit for any single account.
According to the researchers, carrying out the attack would have required only a few hundred XRP to establish the accounts, along with transaction fees. Most of the initial XRP used could subsequently have been recovered.
Developers addressed the vulnerability in version 3.4.1 of xrpld, the XRP Ledger’s server software, released on Sept. 25. The update was initially published without revealing the precise security issue it fixed.
The incident is part of a broader series of long-standing cryptocurrency vulnerabilities uncovered with the assistance of artificial intelligence since July. Other cases include a Coldcard wallet flaw linked to the theft of at least 1,367 BTC and security vulnerabilities that led Core Lightning to advise Bitcoin node operators to disconnect their systems.

































