Critical XRPL Bug Would Have Allowed Creation of 18 Trillion XRP; Emergency Patch Deployed
A severe vulnerability discovered in the XRP Ledger could have allowed an attacker to mint up to 18 trillion XRP, putting an estimated $94 billion in value at risk. Ripple took emergency action to address the flaw before it could be exploited, and a bounty hunter played a role in surfacing the issue. The incident has been described as the largest near-miss security event in crypto history.
A critical security vulnerability was identified in the XRP Ledger that, if exploited, would have permitted any actor to create approximately 18 trillion XRP out of thin air. The potential exposure was estimated at around $94 billion, making it one of the most severe undiscovered bugs ever found in a major blockchain network.
Ripple took emergency action after the vulnerability was reported, containing the threat before any malicious exploitation could occur. The coordinated response prevented what could have been a catastrophic and irreversible inflation of XRP supply.
A bounty hunter is credited with discovering and disclosing the vulnerability, highlighting the role of responsible disclosure programs in protecting open ledger infrastructure. Full technical details of the flaw are being broken down for the broader community.
The incident raises significant questions about the ongoing security audit processes for the XRPL codebase. While no funds were lost and the ledger continued to operate, the event underscores the systemic risk that undiscovered protocol-level bugs can pose to even established blockchain networks.
Key facts
- •A bug in the XRP Ledger could have allowed creation of 18 trillion XRP
- •Estimated $94 billion in value was at risk
- •Ripple took emergency action to resolve the vulnerability
- •No exploitation of the bug occurred
- •A bounty hunter is credited with discovering and disclosing the flaw
- •Described as the largest near-miss security event in crypto history