⚡ LIVE
BTC Loading...

XRP Ledger patched decade-old bug that could create billions of dollars in XRP from nothing


An attacker would open hundreds of accounts, have each one offer a tiny amount of a token in exchange for an unusually large amount of XRP, then send a single payment that bought every offer at once.

The total XRP owed would be too large for the software to count correctly, so the attacker’s selling accounts would be paid in full while the buying account was charged almost nothing — leaving the attacker with XRP that hadn’t existed before.

How one payment could have printed XRP from nothing. (Shaurya Malwa/CoinDesk)

The XRP Ledger runs a check after every transaction to make sure no new XRP has appeared, but that check relied on the same miscounted total and would have missed it. A separate limit on how much XRP a single account can receive wouldn’t have triggered either, because the attack spread the XRP across hundreds of accounts.

The researchers’ method needed only a few hundred XRP to open those accounts, most of which could be recovered, plus transaction fees.

Developers shipped the fix in xrpld 3.4.1, the ledger’s server software, on Sept. 25 without disclosing what it repaired.

The incident joins a run of long-hidden crypto security flaws surfaced with AI help since July, including the Coldcard wallet bug behind the theft of at least 1,367 BTC and the vulnerabilities that forced Core Lightning to tell bitcoin node operators to disconnect.



Source link

BTCLFGTEAM
@Bitcoinlfgo

Follow on X →
⚡ Disclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry significant risk. Always do your own research (DYOR) before making any investment decisions.

Leave a Reply

Your email address will not be published. Required fields are marked *