News On-chain

XRP Ledger Patches 2015-Era Bug That Could Mint XRP Out of Thin Air

An overflow in the XRP Ledger payment engine could mint XRP beyond the 100B cap. Reported Sept. 22, fixed in xrpld 3.4.1 on Sept. 25, disclosed Oct. 9.

XRP Ledger Patches 2015-Era Bug That Could Mint XRP Out of Thin Air

XRP Ledger developers have patched a critical vulnerability that could have created XRP out of thin air, breaking the network's fixed supply cap of 100 billion tokens. The bug was reported on September 22, 2026, the fix shipped in xrpld 3.4.1 on September 25, and a public disclosure report followed on Friday, October 9. "We have found no evidence that this issue was exploited on any public network," the team wrote. The flaw likely dates back to 2015, when the current payment engine was written.

Details

The issue was submitted through the XRPL bug bounty program by researcher Cayden Liao and Veria AI. It came down to arithmetic: when a single payment crossed the ledger's built-in exchange and consumed many offers in a row, the engine summed the amounts with unchecked 64-bit addition. With a large enough set of offers the total wrapped around to a small number, so the buyer was charged only that truncated amount while every seller was paid in full, and the difference appeared from nowhere. The built-in "no XRP created" invariant used the same arithmetic and missed it, and the per-account receiving limit never triggered because the coins were spread across hundreds of addresses, CoinDesk reports.

The report was first rated Major, but RippleX engineers reproduced the attack on a standalone server, confirmed the minted XRP could be spent in a later transaction, and raised the severity to critical. The fix was written and reviewed within two days, merged into the release branch on September 23 and shipped as xrpld 3.4.1 on September 25. By that same day, according to the report, more than 80% of validators on the default UNL were already running the new version. The payment engine now checks for overflow when summing offers and payment paths, and the invariant uses a wider counter that cannot wrap.

How the patch was delivered is notable in itself. Changes to transaction processing on the XRP Ledger normally go through the amendment process, with validator voting and a two-week activation window. This time the fix went straight into the code: the report calls it the first time a transaction-processing change has deliberately bypassed amendments since they were introduced, because the alternative would have left a publicly visible, exploitable hole live on mainnet for weeks. The same report closes a second, less dangerous bug in wrapper validation for the Batch feature; its fix, fixBatchV1_2, was activated on mainnet on October 9.

What it means for the market

For XRP, one of the largest cryptocurrencies, the episode cuts both ways. The worrying part is that a bug capable of breaking the fixed-supply promise sat for a decade in heavily used code. The reassuring part is that only three days passed between the report and most validators upgrading, and disclosure waited until the network was safe. The team says it will add a re-verification step to releases, retesting every finding marked as fixed against the release candidate.

The case also feeds this autumn's wider debate about key and code security: as automated bug hunting improves, more dormant flaws will surface, and response speed becomes its own measure of trust in a chain.

Morning brief and news on TelegramEvery morning: price, scenario of the day, squeeze risk. Key news during the day.
Coins
Category
Tags
#XRP Ledger#vulnerability#RippleX#xrpld#bug bounty
Ryan Mitchell
On-chain and mining

Breaks down blockchain and mining data: hashrate, difficulty, holder and whale behavior.

Read next