XRP Ledger Closed a Decade-Old Bug That Could Have Broken Its 100 Billion Cap
• October 10, 2026 7:07 am • CommentsThe XRP Ledger just closed one of the most dangerous kinds of blockchain bugs: a flaw that could have broken the promise that no more than 100 billion XRP can exist.
The good news is just as important as the vulnerability itself. Developers say they found no evidence that anybody used it on a public network, and the fix was already widely deployed before the technical details became public.
According to the official XRP Ledger vulnerability disclosure, the problem lived in the payment engine that routes transactions through the ledger’s built-in exchange. An attacker could have prepared hundreds of deliberately distorted offers and then consumed them in one payment.
When the software added the amounts together, the total could overflow its 64-bit counter and wrap back to a tiny number.
That accounting failure created the nightmare scenario: the offer owners could receive their full XRP while the buyer paid almost nothing. The difference would become new, spendable XRP that had never existed before.
The report says the overflow could not happen during an ordinary payment. An attacker would have needed hundreds of controlled accounts, deliberately mispriced offers and one transaction designed to consume them together.
Investigators reproduced the process on a standalone server and confirmed that the created XRP could be spent in a later transaction. They also found that the setup cost was limited largely to recoverable account reserves and ordinary fees.
Why the usual safety checks would not have stopped it
XRPL already had a safeguard meant to catch transactions that create XRP. But the official report says that check used the same kind of arithmetic and could overflow in the same way.
A second limit on individual balances would not have helped because the attack spread the newly created XRP across hundreds of accounts.
This was not something an ordinary payment could trigger by accident. It required carefully engineered offers at absurd prices, plus a payment built to sweep them together.
Even so, the setup reportedly needed only a few hundred XRP in recoverable reserves and normal fees. That combination—low cost, no privileged access and potentially catastrophic damage—is why RippleX classified the issue as critical.
XRP Ledger Operations confirmed that version 3.4.1 is now the minimum release and pointed operators to the public disclosure.
XRP Ledger version 3.4.1 is now the minimum required version after the recent amendments were activated.
This release patched critical parts of the XRP Ledger.
The vulnerability report can be found here:https://t.co/sYIwuDomjY
Public release notes:https://t.co/JqX4UYDDg6 pic.twitter.com/pH9Gnsnpqi— XRP Ledger Operations (@XRPLOperations) October 10, 2026
The quiet patch was deliberate
The bug was reported through the XRPL bounty program on September 22. RippleX reproduced it that day, confirmed that the newly created XRP could be spent and raised the severity from major to critical.
Engineers built and reviewed a fix, merged it September 23 and released xrpld 3.4.1 on September 25.
The team did not use the ledger’s normal amendment process. That process would have exposed the patch in open-source code before it had activated across the network, effectively publishing a map to the vulnerability while servers were still exposed.
Instead, operators upgraded directly. The disclosure says more than 80% of validators on the default Unique Node List were running the fixed version by the release date.
CoinDesk adds that the flaw appears to date to 2015, when the current payment engine was written. That longevity is unsettling, but it also explains why the response had to balance transparency against the danger of revealing a cheap exploit too early.
The report notes that all 100 billion XRP were created when the ledger launched and that the software is designed to prevent any additional supply. That made this overflow different from a routine outage or temporary transaction failure.
It also explains why the team shipped a direct software fix instead of waiting through the normal amendment vote. Publishing the code first would have shown attackers exactly where to look while some servers were still vulnerable.
The scale of the theoretical risk quickly caught the market’s attention.
JUST IN: Ripple fixed unexploited 2015 bug that would have allowed billions of $XRP to be minted from nothing – blog. pic.twitter.com/fGCISIwpzU
— Whale Insider (@WhaleInsider) October 10, 2026
The fix matters more than the scare
A fixed-supply asset depends on its accounting rules being absolute. If one payment can manufacture units, the bug strikes at the economic premise institutions and holders rely on.
That did not happen here. The vulnerability was found, reproduced privately, patched quickly and disclosed after the network had protection.
Server operators now need version 3.4.1 or newer. Ordinary XRP holders do not need to take a special action because of this report.
The episode should still change how people think about mature blockchains. Ten years of operation does not prove every edge case is safe.
The stronger signal is whether researchers are rewarded for finding those cases and whether developers can coordinate a responsible fix before attackers get there. On that test, XRPL just survived a very serious one.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
