XRP Ledger Emergency Patch Triggers Decentralization Debate as XRP Kuwait Rejects Control Claims

  • RippleX released xrpld 3.4.1 to address a critical XRP Ledger payment vulnerability.
  • About 18 trillion XRP could have been created through one unauthorized transaction.
  • More than 80% of default UNL validators upgraded before the vulnerability was publicly disclosed.

The XRP Ledger patched a critical integer-overflow flaw that could have enabled the unauthorized creation of about 18 trillion XRP in one transaction. RippleX deployed xrpld 3.4.1 on September 25, three days after Veria Labs reported the vulnerability, and more than 80% of validators on the default Unique Node List had upgraded. Existing accounts estimated the potential issuance at approximately 18.45 trillion XRP, creating a discrepancy between reported figures. The vulnerability involved specially constructed sell orders and a payment-engine calculation error that could have allowed sellers to receive XRP while buyers paid only a negligible amount. A related supply-verification weakness could have failed to block the illegitimate issuance. No evidence of exploitation on the public network has been found. The emergency patch bypassed the usual amendment-voting process, intensifying debate over XRPL decentralization; XRP Kuwait rejected claims that coordinated upgrades demonstrated centralized control. RippleX said it plans to expand AI-based vulnerability detection and formal verification after the incident.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.