
Researchers showed how a single payment on the XRP Ledger could create spendable XRP without the sender funding it — a flaw, believed to date to 2015, that broke the token's fixed 100 billion supply. The vulnerability exploited a counting error in the ledger's built-in exchange, letting an attacker open hundreds of accounts, offer a tiny amount of one token for large amounts of XRP, and buy every offer at once so sellers were paid in full while the buyer was charged almost nothing.
CoinDesk