Ripple Warns of AI Threat After Bug That Could Have Minted Billions of XRP

XRP
XRP Ledgerbug bountyRipple
2 hours agoSource: u.today
Ripple Warns of AI Threat After Bug That Could Have Minted Billions of XRP

Mayukha Vadari, an engineer with RippleX, has warned about the increasing security threats with the advent of artificial intelligence. This comes after developers identified a critical vulnerability in XRP Ledger (XRPL) that would have enabled attackers to mint trillions of XRP from thin air.

"Things have changed with AI. You can't just sneak in a critical bug patch in a regular public release process, because you're going to get caught and reverse engineered right away," Vadari said in a recent post on X.

Vadari’s statement comes in the wake of XRP Ledger’s dev team publicly unveiling the details of a critical vulnerability that was present for a decade and could have affected XRP’s fixed supply of 100 billion tokens.

Details of the XRP Ledger bug

The vulnerability was identified on Sept. 21 by Veria AI. Veria AI is an artificial intelligence-based security system developed by Veria Labs. The next day, researchers filed a bug report through the XRP Ledger bug bounty program.

According to Veria Labs, the vulnerability allowed attackers to mint a staggering 18.45 trillion XRP through a single transaction, over 184 times the initial supply of the cryptocurrency.

Notably, newly minted XRP could have been spent and transferred to various cryptocurrency exchanges.

Based on their findings, security researchers believed that the vulnerability could have impacted the whole market cap of XRP, which they estimated at around $94 billion when they filed the report.

However, the developers of the XRPL have not come across any evidence of exploitation of the vulnerability on the public network.

Trillions of XRP could have been created through the XRP Ledger bug

According to official disclosure of the vulnerability, the critical issue was an integer overflow in XRP Ledger’s payment engine.

The issue was traced back to the code that was added in 2015 and it pertained to the method of calculating payment amounts for processing multiple offers on the network through the decentralized exchange.

This allowed the attacker, under certain circumstances, to generate hundreds of specially crafted trading offers with abnormally high values of XRP.

If processed as a group, the total payment amount of these trading offers could overflow the 64-bit integer calculations of the system.

However, instead of rejecting the transaction, there would be an overflow in the calculation leading to a much lower figure.

As a result, sellers of the assets could have received the full amount of XRP, whereas the buyer would only be charged a miniscule amount as a fraction of the total amount.

To make matters worse, even the XRP Ledger’s native mechanism that’s supposed to prevent the minting of XRP from thin air was plagued by a similar issue with calculations.

Controversial security measure

The discovery of the issue has led the developers of the XRPL to take an unorthodox path to fix the vulnerability.

The development team has released an emergency update – xrpld 3.4.1 – on Sept. 25. However, they have kept the source code of the update with security fixes in abeyance for now.

This move has led to some criticism in the cryptocurrency world over whether it’s consistent with the open-source nature of the network to share binaries of the software without immediately making the code public.