XRPL has disclosed a critical payment-engine bug that could have allowed an attacker to create spendable $XRP beyond the network’s fixed 100 billion supply.

The issue came from an unchecked 64-bit calculation when one payment consumed hundreds of specially crafted order-book offers.

Once the total crossed the integer limit, the value wrapped around to a much smaller number, allowing the system to credit large XRP amounts while charging the buyer only a tiny amount.

The vulnerability affected xrpld 3.4.0 and earlier and was fixed in version 3.4.1, released on September 25.

XRPL says there is no evidence the flaw was exploited on any public network. Triggering it also required a highly specific setup that normal payments would not reach.

#XRPLedger #Altcoin Season# #Macro Insights#