RippleX patched a critical calculation overflow bug dating to 2015 in the XRP Ledger payment engine that could have allowed attackers to mint spendable XRP from nothing and undermine the cryptocurrency's fixed 100 billion token supply cap. Discovered by researcher Cayden Liao and Veria AI via the XRPL Bug Bounty program on September 22, 2026, the issue was fixed in xrpld version 3.4.1 released on September 25. RippleX confirmed no evidence of public network exploitation or loss of funds.
Payment engine vulnerability details
- ▪The payment engine flaw dating to 2015 bypassed post-transaction total XRP balances checks and individual account receipt limits by distributing created XRP across hundreds of separate accounts
- ▪The XRP Ledger payment engine contained a calculation overflow bug dating back to 2015 that could allow an attacker to create new, spendable XRP beyond its total supply
- ▪The XRP Ledger payment engine vulnerability dating to 2015 threatened the XRP cryptocurrency fixed supply of 100 billion tokens established at the XRP Ledger launch in 2012
- ▪A critical XRP Ledger payment engine vulnerability dating to 2015 occurred when combining hundreds of offers with high prices caused the XRP requirement calculation to overflow, charging the buyer less than the amount credited
Patches and mainnet fixes
- ▪RippleX released xrpld version 3.4.1 on September 25, 2026, adding calculation overflow checks to fix the XRP Ledger payment engine vulnerability dating to 2015
- ▪XRP Ledger developers and validator operators activated the corrected fixBatchV1_2 amendment on the mainnet on October 9, 2026, resolving the Batch transaction flaw
Debatable claims
- ▪RippleX's leading role in emergency security fixes highlights centralized governance over the XRP Ledger
- ▪Core blockchain teams should silently patch critical vulnerabilities before public disclosure
- ▪The unexploited XRPL bug poses a credible threat to investor trust in the token's hard supply cap
Story comments
Loading comments…