XRP Ledger Patches 11-Year-Old Bug That Could Have Created Unlimited XRP

iconCoinpaper
Share
AI summary iconSummary
XRP Ledger released on-chain news about a critical 11-year-old bug that could have let attackers create unlimited XRP. The flaw, an integer overflow in the payment engine, was patched on September 25, 2026, with an emergency update to xrpld 3.4.1. No exploitation was detected before the fix. The update bypassed the standard amendment process due to the severity of the vulnerability news.

According to an official disclosure published October 9, the vulnerability could have been exploited through specially constructed transactions. Developers patched the issue on September 25 and found no evidence of exploitation on public networks.

How an 11-Year-Old Bug Threatened XRP's Supply

The vulnerability involved an integer overflow in XRPL's payment engine, which processes transactions involving different assets. When a payment consumed hundreds of specially constructed offers, the software could incorrectly calculate the total XRP owed.

Instead of rejecting a calculation exceeding its numerical limit, the system could wrap the amount around to a much smaller number. Recipients would receive their full payments, while the sender would be charged only the incorrectly calculated total.

The difference could effectively create XRP from nothing, bypassing the cryptocurrency's intended supply restrictions. More concerningly, the ledger's existing protection against unauthorized XRP creation relied on the same vulnerable arithmetic, meaning the manipulation could escape detection.

Researchers reproduced the vulnerability during controlled testing and confirmed that improperly created XRP could subsequently be transferred.

A critical XRPL bug could have created unauthorized XRP, but was patched before exploitation.

XRPL Developers Released Emergency Security Fix

The issue was reported September 22 through XRPL's bug bounty program by Cayden Liao and Veria AI. Engineers initially classified it as a major vulnerability before upgrading its severity to critical.

The September 25 release of xrpld version 3.4.1 introduced additional overflow checks and strengthened the supply-safety mechanism. Unlike standard XRPL protocol changes, the patch became effective immediately as validators upgraded their software.

Ordinarily, amendments require more than 80% validator support for two consecutive weeks. Developers determined that following the usual process could expose the vulnerability before sufficient protection was in place.

More than 80% of validators on the default trusted-validator list had upgraded by September 25. Coinpaper previously covered the emergency XRPL security release, although the full technical implications were not public at that time.

What Does the Vulnerability Mean for XRP Holders?

The disclosure raises questions about how a critical supply-related flaw remained undetected for approximately 11 years. However, researchers emphasized that exploitation required unusually constructed transactions involving hundreds of offers, rather than ordinary XRP transfers.

The October 9 report also detailed a separate Batch transaction vulnerability capable of disrupting network consensus. That issue was addressed through the fixBatchV1_2 amendment, which activated alongside BatchV1_1 on October 9.

The incident follows earlier XRPL upgrade delays and highlights ongoing questions about XRPL governance, particularly when emergency security changes require rapid coordination.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.