XRP Ledger Discloses Critical Bug That Could Have Created New XRP

iconCoinpedia
Share
AI summary iconSummary
The XRP Ledger (XRPL) revealed two software bugs on October 9, 2026, including a critical flaw that could have let attackers generate new XRP. A second issue impacted the Batch transaction system, possibly causing validation problems. The payment engine fix was released in xrpld 3.4.1 on September 25. No on-chain news suggests the flaw was used in public networks. New token listings remain unaffected by the update.

The XRP Ledger (XRPL) disclosed two software vulnerabilities on October 9, 2026, including a critical bug that could have allowed attackers to create new, spendable XRP. The second flaw affected the network’s Batch transaction feature and could have disrupted transaction validation.

According to the official report, the payment engine bug was fixed in xrpld version 3.4.1, released on September 25. XRPL reported no evidence that the vulnerability had been exploited on any public network.

XRPL Bug Could Have Created New XRP

The critical vulnerability affected how the payment engine calculated the XRP required to complete trades across multiple offers in an order book. The calculation could overflow when the combined amount exceeded the maximum value supported by the system. This could cause the payment engine to charge a buyer less XRP than the amount credited to offer owners, effectively creating new XRP.

Exploiting the bug required a carefully prepared order book containing hundreds of offers with unusually high prices, followed by a specific payment transaction. The vulnerability could not be triggered through ordinary payments or trades.

A researcher reported the issue through the XRPL Bug Bounty program on September 22, 2026. The RippleX engineering team reproduced the bug and confirmed that any XRP created through the flaw could be spent.

The issue was fixed in version 3.4.1. Developers added checks to prevent the calculation from overflowing and strengthened the system’s safeguards against unauthorized XRP creation.

Second Bug Affected XRPL Batch Transactions

The second vulnerability involved the XRP Ledger’s Batch transaction feature, which allows users to submit multiple transactions together. The flaw allowed a transaction inside a batch to use an incorrectly structured field. The server could still accept and process the transaction.

This created a risk that different versions of XRPL software could disagree on whether a transaction was valid. Such disagreements could prevent validators from reaching consensus and interrupt ledger validation.

The issue did not allow attackers to bypass transaction signatures or directly steal funds, according to the report.

XRPL addressed the flaw through the fixBatchV1_2 amendment, which requires transactions to use the correct structure. The Batch feature had not been activated on the mainnet when the vulnerability was identified, so the report did not identify any mainnet accounts or funds affected by this bug.

XRPL Activates Batch Security Fix

XRPL developers and validator operators withdrew support for the original Batch amendment to reset its activation timeline while the team prepared the fix.

The corrected amendment gained support and activated on the mainnet on October 9, 2026, the same day the vulnerability report was published.

The report also outlined a change to the security testing process. XRPL plans to retest reported vulnerabilities against release candidates to confirm that fixes work before software releases.

What XRP Holders Need to Know

Both vulnerabilities have been addressed, and XRPL reported no evidence that the critical payment engine bug had been exploited on a public network. The report does not establish that either flaw caused an actual loss of funds or an increase in XRP supply. The payment engine fix is included in xrpld version 3.4.1, while the Batch issue was addressed through the fixBatchV1_2 amendment.

The report does not instruct XRP holders to move their funds or change their private keys. The software upgrade is relevant to XRPL server operators, who need compatible versions to remain synchronized with the network.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.