Ripple Patches Critical XRP Ledger Vulnerability That Could Have Allowed Billions of XRP to Be Mined

iconBitcoinsistemi
Share
AI summary iconSummary
RippleX, Ripple’s development team, addressed a critical vulnerability news in the XRP Ledger (XRPL) that could have let attackers mine billions of XRP for free. The flaw, a 64-bit integer overflow in the payment engine, allowed bypassing cryptocurrency rules around XRP’s supply. Discovered on September 22, 2026, it was patched in xrpld 3.4.1 and fixBatchV1_2 on October 9. RippleX confirmed the issue in a test environment but found no signs of public network exploitation. A second vulnerability in batch processing was also fixed, preventing potential block verification problems.

Ripple’s development team, RippleX, announced that they have patched a critical security vulnerability in the XRP Ledger (XRPL) network that is believed to have existed for approximately 11 years and could have allowed attackers to mine billions of XRP without paying anything.

According to a security report published on October 9th, a software flaw was discovered in the XRP Ledger’s payment engine, believed to have existed since 2015. This vulnerability could have allowed malicious actors to violate XRP’s supply rules, create new coins, and spend them as if they were regular XRP.

RippleX stated that there is no evidence that the vulnerability has been exploited on any public network.

Attackers Could Have Generated Billions of XRP

On September 22, 2026, a security vulnerability reported under the XRP Ledger bug bounty program was identified as stemming from a 64-bit integer overflow error in the payment engine.

Normally, the XRP Ledger has security controls that prevent the creation of new XRP. However, researchers have shown that these controls can be bypassed if hundreds of specially crafted buy and sell orders are used in a single payment transaction.

In this scenario, the system was able to fully process XRP payments to order holders while only collecting a very small portion of the actual amount due from the recipient.

Moreover, the security mechanism that checks whether new XRP was created was also affected by the same mathematical error, allowing transactions to be deemed valid.

RippleX engineers recreated the vulnerability in an independent test environment, confirming that XRP extracted using this method could be spent in subsequent transactions.

According to the report, initially only a few hundred XRP would have been enough to reserve in accounts and orders to carry out the attack. However, the attack required specific conditions that could not have occurred spontaneously through normal market transactions.

Related News: BREAKING: Security Vulnerability Discovered in Popular Altcoin - Block Production Halted

Ripple Patches Yet Another Security Vulnerability

The security report explained that, in addition to the error that could lead to XRP mining, another security vulnerability in the batch processing mechanism was also fixed.

This bug, reported on September 18th, was capable of causing validators using different software versions to evaluate the same operation differently.

In such a situation, the verification of new blocks on the XRP Ledger network could temporarily stop.

However, since the feature in question had not yet been enabled on the main network when the vulnerability was discovered, no user balances were affected and there were no reconciliation issues on the network.

Both vulnerabilities were fixed in xrpld version 3.4.1, released on September 25th. The fixBatchV1_2 update, which enables a fix related to the batch mechanism, was deployed on the mainnet on October 9th.

*This is not investment advice.

Continue Reading: Ripple (XRP) Avoids Disaster: Security Vulnerability Discovered That Could Allow Billions of XRP to Be Mined

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.