The XRP Ledger has disclosed a critical bug that could have let an attacker create XRP out of thin air, beyond the network’s hard limit of 100 billion tokens.
The flaw lived in xrpld versions 3.4.0 and earlier. It was patched quietly in September and made public on October 9, 2026. Investigators found no evidence it was ever used on a public network.
How the bug worked
The software used a 64-bit integer to add up XRP amounts when a single payment pulled from multiple offers on the order book. If that running total grew past the largest number the integer could hold, it wrapped around. The result was a number far smaller than reality.
An attacker could exploit that gap to spend XRP that did not exist. The ledger’s books would look balanced, while the actual supply quietly ballooned. The existing safety checks did not catch it. When the inflated balances were scattered across many accounts, the system’s guardrails failed to flag the discrepancy.
The cost of pulling this off was strikingly low. According to the disclosure, the exploit required specially crafted offers from hundreds of accounts, costing only a few hundred XRP in reserves and fees. Most of that outlay would have been recoverable.
The amount of XRP that could have been minted in a single transaction may have exceeded the token’s entire total supply.
A quiet fix, then a public disclosure
The vulnerability was reported on September 22, 2026, by researcher Cayden Liao through the XRPL Bug Bounty program. RippleX, Ripple’s developer arm, confirmed the issue.
RippleX reproduced the attack on a standalone server and confirmed that the excess XRP could be spent in follow-up transactions.
Three days after the report, on September 25, 2026, an emergency release went out: xrpld 3.4.1. The fix also skipped the usual amendment process. Normally, changes to the XRP Ledger’s rules go through a validator voting procedure before taking effect. This one was deployed immediately instead.
The public disclosure came on October 9, roughly two weeks after the patch shipped. The team reported no loss of funds, no compromised keys and no consensus problems tied to the bug.
A decade in hiding
The flaw is thought to have existed since the payment engine was first built, around 2015. That means the code processed payments for years with a latent overflow sitting inside it.
What this means for XRP holders and the ledger
For XRP holders, the immediate takeaway is reassuring. There is no evidence the bug was exploited, and the integrity of the token supply appears intact.
The decision to bypass the amendment process deserves attention. A known path to unlimited XRP creation is not something you want waiting on a governance vote. Emergency patches that skip normal procedures put a lot of trust in the core development team, and the network’s security depended on validators and node operators upgrading quickly.
Node operators still running xrpld 3.4.0 or earlier are the most direct audience for this news. The patched version, 3.4.1, has been available since September 25, and anyone who has not upgraded is running software with a publicly documented supply-breaking flaw.
Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.

3 hours ago
17








English (US) ·