XRP Ledger Found a Bug That Could Create XRP

1 hour ago 3

Rommie Analytics

Key Takeaways

  • A payment overflow could have created spendable XRP.
  • XRPL found no evidence the flaw was exploited.
  • The patch shipped in xrpld 3.4.1 on September 25.
  • Developers bypassed the normal amendment timeline to close the risk faster.

A payment calculation could produce XRP from nothing

XRPL’s October 9 vulnerability report describes an integer-overflow flaw in the ledger’s payment engine. Under carefully constructed conditions, a payment that consumed many order-book offers could have credited accounts with XRP that the sender had not actually paid.

Each offer in the transaction could appear valid on its own. The failure arose when the engine added the XRP amounts across all of them. Once the total exceeded the maximum size of the number used for that calculation, it could wrap around to a much smaller value instead of producing an error.

The engine would still credit the offer owners with their full XRP amou...

Read Entire Article