Researchers discovered a flaw in the XRP Ledger’s native exchange that miscounted token amounts during a large-scale purchase. By opening hundreds of accounts and posting tiny offers for a massive amount of XRP, an attacker could have triggered a miscalculation that left the buyer virtually unpaid while the sellers received the full XRP amount. The error bypassed the ledger’s post-transaction check and any per-account receipt limits because the newly created XRP was distributed across many accounts.

How the issue was identified and addressed

The problem was first reported internally on Sept. 22 after a security analysis by Cayden Liao and Veria AI. Ripple’s development team reproduced the attack on an isolated server, confirming that the fabricated XRP could be moved in subsequent transactions. RippleX announced that no evidence of the bug being used on any live network existed. To remediate the vulnerability, engineers delivered an update to the xrpld server software—version 3.4.1—on Sept. 25, correcting the counting logic in the exchange module.

Potential impact if left unpatched

XRP’s supply is capped at 100 billion tokens, a figure that underpins its appeal to institutional users. Had the bug been exploited, attackers could have minted billions of dollars’ worth of XRP without cost, destabilizing market confidence and threatening the token’s scarcity premise. The attack required only a modest amount of XRP to seed the accounts and standard transaction fees, making it relatively inexpensive to execute.

Why it matters

The patch demonstrates the importance of continual security audits, especially for legacy codebases dating back to the early days of cryptocurrency. It also highlights the growing role of AI-assisted research in uncovering hidden vulnerabilities across the industry. By swiftly fixing the issue and confirming the absence of exploitation, RippleX reinforces trust in the XRP Ledger’s technical integrity and its fixed-supply guarantee.