Critical XRP Ledger Bug in Batch Amendment Could Have Drained User Wallets - U.Today

XRP2,63%
DOGE2,49%
SHIB3,26%

A severe logic flaw within the XRP Ledger (XRPL) codebase was narrowly averted this month, a recent blog post states

Security researchers discovered a vulnerability that could have allowed attackers to drain user wallets without needing their private keys.

The bug, which was spotted in the proposed “Batch” amendment (XLS-56), was identified earlier this month by independent researcher Pranamya Keshkamat and an autonomous AI security tool named Apex

HOT Stories

Critical XRP Ledger Bug in Batch Amendment Could Have Drained User Wallets

Crypto Market Review: XRP Volatility Squeeze is a $2 Recipe, Will Dogecoin (DOGE) Zero Removal Happen in February? Shiba Inu (SHIB) Bullruns Aren’t Possible Yet

The amendment was still in its voting phase and had not been activated on the XRPL mainnet. Hence, no user funds were at risk or lost.

The vulnerability explained

The Batch amendment would allow multiple “inner” transactions to be grouped together.

These inner transactions are intentionally left unsigned in order to save processing power. Instead, authorization is delegated to the outer batch’s list of signers.

A critical loop error caused a major vulnerability in the process of calling signers.

If the system encountered a signer for an account that did not yet exist on the ledger, and the signing key matched that new account, the system immediately declared the validation a success. It then exited the loop early, avoiding validator checks

A specific sequence of batched transactions could have been used by the attacker to exploit the aforementioned vulnerability

Had the Batch amendment been activated on the mainnet before this discovery, the XRPL ecosystem would have potentially suffered a severe blow. An attacker could have stolen funds, modified the ledge state, and destabilized the ecosystem

Earlier this week, developers released the Rippled 3.1.1 reference server software. This emergency patch explicitly marks the Batch amendment as unsupported,

A comprehensive fix that removes the early-exit loop and adds tighter authorization guards has been developed. It is currently undergoing rigorous peer review

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Articoli correlati

XRP ETF Assets Reach $1.08B as Fresh Inflows Hit $11.87M

XRP exchange traded funds saw inflows of $11.87 million, increasing total assets to $1.08 billion, reflecting sustained institutional interest and confidence in XRP's role in cross-border payments amidst growing demand for crypto ETFs.

GateNews2h fa

ETF Launch Fails to Stem Tide As XRP Sinks to $1.81, Lowest Since April

Crypto asset manager Bitwise’s launch of a spot XRP exchange-traded fund on Nov. 20 failed to lift the token, which fell to $1.81 — its weakest level since April — before a broader Nov. 21 sell‑off drove monthly losses above 20%. ETF Launch Followed by Double-Digit Losses The highly

Coinpedia2h fa

Ripple Executive Details XRP Ledger's Role in Institutional Finance at Paris Blockchain Week

Ripple's Marcus Infiner outlined a strategy for institutional adoption of blockchain at Paris Blockchain Week, emphasizing collaboration between crypto firms and traditional finance. He highlighted the XRP Ledger's compliance and efficiency for cross-border payments and on-chain markets, advocating for integration into existing systems.

GateNews3h fa

SBI Holdings Launches 10 Billion Yen Blockchain Bond With XRP Rewards

SBI Holdings has launched SBI START Bonds, a 10 billion yen blockchain-based bond program for retail investors, offering interest payments and XRP token rewards. The initiative highlights SBI's partnership with Ripple and aims to integrate digital assets into traditional finance.

GateNews5h fa

Garlinghouse Maintains Confident Tone on XRP Throughout 2026

Ripple CEO Brad Garlinghouse has maintained a positive outlook on XRP and regulatory developments throughout 2026, emphasizing institutional interest and the anticipated passage of the CLARITY Act despite XRP's price decline. His public statements highlight momentum in Ripple's business and project confidence in the crypto market's future.

CryptoFrontier8h fa

XRP Trading Volume Surges to $1.81B in Single Session, Holds Above $1.43

XRP trading volume reached $1.81 billion, driven by futures at $1.47 billion and spot trading at $341 million. Currently priced at $1.43, XRP is above the 200-day EMA, signaling bullish momentum and increased market participation.

GateNews16h fa
Commento
0/400
Nessun commento