According to an official disclosure published October 9, the vulnerability could have been exploited through specially constructed transactions. Developers patched the issue on September 25 and found no evidence of exploitation on public networks.
How an 11-Year-Old Bug Threatened XRP's Supply
The vulnerability involved an integer overflow in XRPL's payment engine, which processes transactions involving different assets. When a payment consumed hundreds of specially constructed offers, the software could incorrectly calculate the total XRP owed.
Instead of rejecting a calculation exceeding its numerical limit, the system could wrap the amount around to a much smaller number. Recipients would receive their full payments, while the sender would be charged only the incorrectly calculated total.
The difference could effectively create XRP from nothing, bypassing the cryptocurrency's intended supply restrictions. More concerningly, the ledger's existing protection against unauthorized XRP creation relied on the same vulnerable arithmetic, meaning the manipulation could escape detection.
Researchers reproduced the vulnerability during controlled testing and confirmed that improperly created XRP could subsequently be transferred.
XRPL Developers Released Emergency Security Fix
The issue was reported September 22 through XRPL's bug bounty program by Cayden Liao and Veria AI. Engineers initially classified it as a major vulnerability before upgrading its severity to critical.
The September 25 release of xrpld version 3.4.1 introduced additional overflow checks and strengthened the supply-safety mechanism. Unlike standard XRPL protocol changes, the patch became effective immediately as validators upgraded their software.
Ordinarily, amendments require more than 80% validator support for two consecutive weeks. Developers determined that following the usual process could expose the vulnerability before sufficient protection was in place.
More than 80% of validators on the default trusted-validator list had upgraded by September 25. Coinpaper previously covered the emergency XRPL security release, although the full technical implications were not public at that time.
What Does the Vulnerability Mean for XRP Holders?
The disclosure raises questions about how a critical supply-related flaw remained undetected for approximately 11 years. However, researchers emphasized that exploitation required unusually constructed transactions involving hundreds of offers, rather than ordinary XRP transfers.
The October 9 report also detailed a separate Batch transaction vulnerability capable of disrupting network consensus. That issue was addressed through the fixBatchV1_2 amendment, which activated alongside BatchV1_1 on October 9.
The incident follows earlier XRPL upgrade delays and highlights ongoing questions about XRPL governance, particularly when emergency security changes require rapid coordination.

