Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$82,978▲ 0.52%ETH$2,504▲ 0.82%SOL$109.93▲ 0.32%TOTAL CRYPTO$2.82T▼ 2.29%S&P 5007,811.54▲ 0.59%NASDAQ27,366.17▲ 0.64%DOW51,654.95▲ 0.83%GOLD4,216.30▲ 1.43%WTI91.85▲ 0.39%BRENT104.72▲ 0.42%EUR/USD1.1206▼ 0.06%USD/JPY158.25▲ 0.12%DXY102.23▲ 0.09%
Crypto

XRP Ledger Patched 10-Year Bug That Could Mint XRP

A flaw, present since the ledger's early days, could have let anyone create unlimited XRP. Ripple engineers closed it without any exploit on record.

Pexels – Moose Photos

XRP Ledger developers have patched a vulnerability that had existed for roughly a decade and could, in theory, have allowed a malicious validator to create billions of dollars in XRP out of nothing, according to a report published by CoinDesk on Friday. The fix went live without any known exploitation, and the ledger’s token supply never moved outside normal issuance checks.

The flaw sat in how the ledger validated certain transaction sequences under stress, CoinDesk reported. An attacker who had arranged the right preconditions could have bypassed the supply cap written into the protocol. Ripple’s engineering team, working with external security researchers, closed the hole in a coordinated release that has already been adopted by a supermajority of validators, which is what allows a protocol change to be treated as settled.

How the bug worked

Under normal operation the XRP Ledger enforces a strict rule: no transaction may create XRP, apart from the small fee sink that accumulates burned transaction fees. The decade-old bug would have allowed a carefully crafted transaction batch to sidestep that rule in a narrow set of circumstances, effectively minting new coins from nothing. The exact technical details have been disclosed in limited form, as is standard practice, so that any node still running old software cannot learn how to reproduce the attack from the patch notes alone.

Security researchers involved in the review told CoinDesk the bug surfaced through automated differential testing rather than through anyone attempting an exploit in the wild. Differential testing compares the output of two independent implementations of the same protocol rules; when one accepts a transaction and the other rejects it, something is wrong with the logic. That approach has caught several high-severity bugs across the industry in the past two years, and it works only because XRP Ledger has maintained multiple independent implementations since 2020, when Ripple, the XRP Ledger Foundation and others funded a second client to reduce what was then a single point of failure.

There is no evidence that any funds were lost and no sign of an irregular mint in the ledger’s public supply history, which anyone can audit directly from the chain itself. The supply of XRP today sits at just under 100 million tokens of the 100 billion originally created, with the remainder held in Ripple’s escrow accounts under a schedule that releases a small slice each month.

Why a decade-long window matters

The XRP Ledger went live in 2012, and much of its core logic has remained untouched through successive rewrites of the surrounding software. That longevity is normally a virtue: the network has processed more than a decade of settlement without a single halt, which is a record few open-source financial systems can claim. It also means an old bug can sit quietly in the codebase while the amount of value riding on the network grows into the tens of billions of dollars.

Chains that survive years without a serious protocol exploit, developers often point to Bitcoin and, more recently, XRP Ledger’s own record, are the ones institutional money ends up trusting. A flaw that could mint supply, even if unexploited, sits in the worst category of bug the industry recognizes. The closest precedent is the 2010 Bitcoin value overflow incident, in which a peer of the network briefly created 184 billion BTC in a single transaction before developers pushed out a fix within hours and rolled back the offending block.

The wider pattern of bundled fixes

The disclosure lands amid a wider run of network upgrades across the sector this week. Zcash developers set a January target for quantum-resistant payments after what contributors called a ‘bunker mode’ scare, a stretch in which a research finding suggested advances in AI-assisted mathematics could threaten wallet security sooner than assumed. Solana pushed out a four-stage upgrade cutting block times to 200 milliseconds, layered across many epochs precisely so a mistake can be caught before it becomes irreversible. Privacy researchers have proposed shielded transfers for Bitcoin itself using zero-knowledge proofs, a project that would leave consensus untouched but rewrite the wallet experience.

XRP Ledger’s maintainers said the patch went through the network’s standard governance path: a proposed amendment, a review period, then activation once validator voting thresholds cleared. Validators that had not updated by the deadline simply fell behind the ledger state rather than continuing on a vulnerable version, which is how the network prevents forks from splitting the chain into two incompatible histories.

The XRP token itself traded near $1.40 on Friday, little moved by the disclosure, according to CoinGecko data. Institutional interest in XRP products has grown through 2026, with the CFTC proposing last week to classify XRP and Stellar’s XLM as digital commodities, a designation that would ease some of the regulatory uncertainty that has followed the token since the SEC’s enforcement action against Ripple, though the proposal remains a draft open for comment and the SEC has not signaled its position.

What happens next

Engineers plan a fuller public write-up once the network has fully converged on the patched release, a delay that gives stragglers time to upgrade before the vulnerability details become a how-to guide. Separate work continues on new permission controls for banks and tokenized funds, additions Ripple and the XRP Ledger Foundation have pitched to institutional issuers that have largely stayed on the sidelines of on-chain settlement so far.

The episode is a reminder that ten years of clean operation is a live streak, not a settled fact. It ends whenever someone finds the next old bug, and the only real defense is the boring one: more independent implementations, more automated testing, and a validator base quick enough to patch in days rather than weeks.

Share: X