Prefer Koin Bülteni on Google Add as source

Critical XRP Flaw Patched: Attackers Could Have Created Tokens From Nothing!

RippleX said it found no evidence that the vulnerability, believed to have existed since 2015 and capable of allowing attackers to create XRP out of thin air, had been exploited on public networks as it was patched.

According to a security report published on October 9 and reported by CoinDesk, the flaw was identified by researchers Cayden Liao and Veria AI and reported to developers on September 22. Ripple’s developer division, RippleX, recreated the attack scenario on a separate test server and confirmed that the XRP created this way could be spent in a subsequent transaction.

A fix for the vulnerability was released with xrpld 3.4.1 on September 25. At the time, the update did not specify which bug it addressed; the new report revealed the issue’s far-reaching implications for XRP’s supply rule.

How could the 100 billion XRP limit have been bypassed?

When the XRP Ledger went live in 2012, all 100 billion XRP were created, and the software was designed so that no additional XRP could be added beyond that amount. The identified bug could have bypassed this rule during the calculation of transactions on the network’s built-in exchange.

When exchange offers spread across numerous accounts were processed together, the total amount could exceed the limit the software could calculate correctly. As a result, XRP could be transferred to sellers’ accounts while only a small amount of XRP was deducted from the buyer’s account in return. The difference meant that XRP that had not previously existed could be created.

The security check that verifies after each transaction whether new XRP has been created also used the same faulty calculation, so it could not catch the problem. Distributing the amount across numerous accounts also prevented the per-account limits from blocking this scenario.

RippleX: No evidence of exploitation on public networks

The fact that XRP created in the test environment could later be spent showed that the bug was not merely an issue that displayed an incorrect balance on screen. The vulnerability could also have allowed an attacker to sell newly created XRP on exchanges.

RippleX said it found no evidence that the flaw had been exploited on any public network. While researchers believe the bug may date back to 2015, the released fix closed this avenue, which put XRP’s fixed supply rule at risk.

Tüm gelişmelerden ve paylaşımlardan haberdar olmak için Telegram kanalımıza katılın!