XRPL Reveals Critical Bug That Could Have Minted Spendable XRP
AI Market Summary
XRPL disclosed a critical payment-engine overflow bug that, under crafted order-book conditions, could have created spendable XRP, alongside a separate batch-transaction validation risk. Although fixes are deployed (xrpld 3.4.1 and a mainnet amendment) and no exploitation was observed, the episode highlights protocol-level tail risk and the importance of timely node upgrades. Near-term, this can raise uncertainty premiums and widen liquidity risk around XRP/XRPL activity.
Impact level
● High
Affected assets
XRP/USDT+1.12%
AI Insight · XRP/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
XRPL has disclosed two software vulnerabilities, including a critical flaw that could have allowed an attacker to create new, spendable XRP under specific conditions.
In a report dated Oct. 9, 2026, the XRP Ledger said the most serious issue involved the payment engine’s handling of trades that execute across multiple bids in the order book. If the aggregated amount being calculated exceeded the system’s maximum supported value, an arithmetic overflow could occur. In that scenario, the payment engine might charge a buyer less XRP than the amount credited to the bid owner’s account, effectively creating new XRP.
XRPL said exploiting the bug would have required a carefully prepared order book with hundreds of orders at abnormally high prices, followed by a specific payment transaction. The flaw could not be triggered through ordinary payments or typical transactions.
The issue was reported on Sept. 22, 2026 via the XRPL Bug Bounty Program. RippleX engineers reproduced the behavior and confirmed that any XRP created through the bug could be spent. XRPL said the vulnerability was fixed in xrpld version 3.4.1, released Sept. 25, and added safeguards to prevent overflow and strengthen protections against unauthorized XRP creation. The project said it has found no evidence the issue was exploited on any public network.
XRPL also detailed a separate vulnerability tied to its Batch transactions feature, which lets users submit multiple transactions together. The flaw could allow one transaction inside a batch to include improperly structured fields while still being accepted and processed by a server. That behavior could cause different XRPL software versions to disagree on whether a transaction is valid, potentially preventing validators from reaching consensus and disrupting ledger validation.
XRPL said the Batch-related issue did not enable signature bypasses or direct fund theft. It was addressed through the fixBatchV1_2 amendment, which enforces correct transaction structure. At the time the issue was discovered, the Batch feature had not been activated on mainnet, and the report said no mainnet accounts or funds were affected.
Following the discovery, developers and validator operators withdrew support for the original batch proposal to reset its activation timeline while a fix was prepared. The revised proposal was supported and activated on mainnet on Oct. 9, 2026, the same day the vulnerability report was published.
XRPL said it will also adjust its security testing process, including retesting previously reported vulnerabilities on release-candidate builds to confirm fixes are effective before shipping new software.
For XRP holders, XRPL said both issues have been addressed and the report did not show actual fund losses or any confirmed increase in XRP supply. The payment engine fix is included in xrpld 3.4.1, and the Batch issue is resolved via fixBatchV1_2. The report said XRP holders do not need to move funds or change private keys; the upgrade primarily affects XRPL server operators, who must run a compatible version to remain in sync with the network.
CoinPedia Disclaimer: CoinPedia says it has covered crypto and blockchain since 2017 and that its content is produced under editorial standards based on EEAT (Experience, Expertise, Authoritativeness, Trustworthiness), with fact-checking against reliable sources.
Investment Disclaimer: Views expressed reflect the author’s opinions on market conditions. Readers should do their own research before making investment decisions. Neither the author nor the publisher accepts responsibility for financial outcomes.
Sponsorship and Advertising: The site may include sponsored content and affiliate links. Ads will be labeled, and editorial content is stated to remain independent of advertising partners.