Decade-Old XRPL Vulnerability Patched After Emergency Software Release
A critical security flaw in the XRP Ledger's payment system, potentially dormant for over ten years, has been publicly disclosed and patched. Researchers demonstrated that the bug could have allowed the creation of spendable XRP without the sender funding the transaction. No evidence of exploitation was found before the fix was deployed.
A security report published on xrpl.org, the official developer site for the XRP Ledger, disclosed the existence of a critical vulnerability in the ledger's payment system. The flaw, which may have been present for more than a decade, was serious enough to prompt an emergency software release before public disclosure.
Researchers demonstrated that the bug could allow a payment to create spendable XRP without the sender providing the underlying funds. In effect, this meant that an attacker with knowledge of the flaw could have minted arbitrary amounts of XRP from nothing, undermining the ledger's core supply integrity.
Despite the severity of the vulnerability, investigators stated there is no evidence that any party discovered or exploited it prior to disclosure. The coordinated responsible disclosure process appears to have kept the flaw contained until a patch was ready.
The fix has now been deployed. Developers and node operators are expected to update their software to the patched version. The incident highlights the ongoing importance of independent security research for public blockchain infrastructure, particularly as artificial intelligence tools become increasingly capable of identifying latent code vulnerabilities.
Key facts
- •A critical vulnerability in the XRPL payment system was publicly disclosed via xrpl.org
- •The flaw could have allowed creation of spendable XRP without sender funding the transaction
- •The bug may have existed for over a decade
- •An emergency software patch was released prior to public disclosure
- •No evidence of exploitation was found before the patch
- •Responsible disclosure process was followed