#xrpledgerpatchesxrpcreationbug #XRPLedgerPatchesXRPCreationBug

Critical bug fixed in xrpld 3.4.1 - Sept 25, 2026

BUG since 2015 (10 years!):
Payment engine had integer overflow.
Attacker could:
1. Open 100s of accounts
2. Each offers tiny token for HUGE XRP
3. 1 payment buys ALL offers at once
4. Total XRP owed too big โ†’ counter OVERFLOWS to tiny number
5. Sellers paid FULL, buyer charged almost NOTHING
6. Difference = NEW XRP created from thin air โ†’ spendable!

Ledger's safety check used same flawed math so missed it.
Single-account limit bypassed because XRP spread across 100s accounts.

Cost to attack: few hundred XRP only (recoverable).

Found by Cayden Liao + Veria AI
Reported Sept 22 via Bug Bounty
RippleX reproduced on test server - confirmed spendable
Patched Sept 25 - NO evidence exploited on mainnet

First time in 10+ years Ripple bypassed validator vote amendment - fixed immediately on upgrade to avoid exposing bug in open code.
80%+ validators upgraded on day 1.

Plus 2nd bug fixed: Batch transaction flaw (fixBatchV1_2) - activated Oct 9.

100B XRP supply cap was at risk - now safe.

$XRP P #XRP #XRPL