The XRP Ledger (XRPL) disclosed a serious vulnerability that had existed for 11 years.
Vulnerability timeline:
2015 — The flaw was introduced in code written for the payment engine.
September 22, 2026 — Researcher Cayden Liao and Veria AI reported it through the bug bounty program.
September 25, 2026 — RippleX released the xrpld 3.4.1 fix, which went live within 3 days.
October 9, 2026 — The fixBatchV1_2 amendment activated on the mainnet, completing the final layer of the fix.
How the vulnerability worked:
The payment engine used a 64-bit integer to add up the amount of XRP a payment pulled from the order book. If this total exceeded the maximum value of a 64-bit integer, it would "overflow to zero"—starting the calculation again from a tiny number.
An attacker could set up hundreds of accounts, place orders to "exchange tiny amounts of tokens for large amounts of XRP," then use a single payment to consume all those orders at once. After the counter overflowed, the sellers' accounts would receive the full amount of XRP, while the buyer's accounts would pay almost nothing—the difference would be XRP created out of thin air.
In theory, this could have breached XRP's total supply cap of 100 billion.
Key fact: No evidence of exploitation on the public network.
The vulnerability ran in production for 11 years without being discovered or exploited.
The fix bypassed XRPL's usual amendment voting process—which requires support from 80% of validators for two consecutive weeks—because a public vote would have exposed the vulnerability's details in advance, creating greater risk. By September 25, more than 80% of default trusted validators were already running the fixed version.
The XRP price showed no significant reaction—the market viewed this as "a theoretical vulnerability being closed," rather than "an actual loss occurring."
Still, this is worth recording: a vulnerability that could have enabled unlimited XRP issuance remained undetected for 11 years on the largest non-Bitcoin payments network.
$XRP
#XRPL
#xrp账本修复可增发xrp的漏洞
Vulnerability timeline:
2015 — The flaw was introduced in code written for the payment engine.
September 22, 2026 — Researcher Cayden Liao and Veria AI reported it through the bug bounty program.
September 25, 2026 — RippleX released the xrpld 3.4.1 fix, which went live within 3 days.
October 9, 2026 — The fixBatchV1_2 amendment activated on the mainnet, completing the final layer of the fix.
How the vulnerability worked:
The payment engine used a 64-bit integer to add up the amount of XRP a payment pulled from the order book. If this total exceeded the maximum value of a 64-bit integer, it would "overflow to zero"—starting the calculation again from a tiny number.
An attacker could set up hundreds of accounts, place orders to "exchange tiny amounts of tokens for large amounts of XRP," then use a single payment to consume all those orders at once. After the counter overflowed, the sellers' accounts would receive the full amount of XRP, while the buyer's accounts would pay almost nothing—the difference would be XRP created out of thin air.
In theory, this could have breached XRP's total supply cap of 100 billion.
Key fact: No evidence of exploitation on the public network.
The vulnerability ran in production for 11 years without being discovered or exploited.
The fix bypassed XRPL's usual amendment voting process—which requires support from 80% of validators for two consecutive weeks—because a public vote would have exposed the vulnerability's details in advance, creating greater risk. By September 25, more than 80% of default trusted validators were already running the fixed version.
The XRP price showed no significant reaction—the market viewed this as "a theoretical vulnerability being closed," rather than "an actual loss occurring."
Still, this is worth recording: a vulnerability that could have enabled unlimited XRP issuance remained undetected for 11 years on the largest non-Bitcoin payments network.
$XRP
#XRPL
#xrp账本修复可增发xrp的漏洞
